What a VPN changes about your browsing, and what it leaves exactly as it was
VPN marketing has settled on a single promise: privacy, anonymity and safety, purchased monthly. The published guidance from national security bodies describes something much narrower. NCSC scopes a VPN to providing "secure connectivity between devices in physically separate locations" and guaranteeing the security of "data in transit" across an untrusted network — with the caveat that "only traffic which is routed over the VPN will be protected by it." That is a real benefit. It is a much smaller one than the advertising implies.
The scope, as published
- NCSC: a VPN guarantees the security of "data in transit" across an untrusted network — and "only traffic which is routed over the VPN will be protected by it."
- NCSC recommends a protocol, not a product: "Our recommendation is that IPsec be used for VPN access. IPsec is an open standard".
- NCSC warns that "using a third-party VPN client increases the risk that operating system integration will be poor, and that consequently, some data may be sent outside the VPN."
- The FTC’s current public Wi-Fi safety article does not mention VPNs at all — its advice is HTTPS, strong passwords, two-factor authentication and spotting fraudulent sites.
- The FTC’s reason: "Today, most websites do use encryption to protect your information", so "connecting through a public Wi-Fi network is usually safe."
The claim on the homepage
The pitch is familiar enough to recite. Browse anonymously. Stay safe on public Wi-Fi. Stop anyone tracking you. Hide from your internet provider. Some of that is a fair description of one narrow effect, stretched across an entire product category.
Worth noting where the guidance is silent. NCSC’s VPN material addresses enterprise deployment and contains no endorsement of commercial consumer VPN services. The FTC’s public Wi-Fi article — the exact scenario VPN advertising leans on hardest — does not mention VPNs anywhere.
What the tunnel genuinely does
Strip the marketing and one mechanism remains. Your traffic is encrypted from your device to a server somewhere else, and emerges onto the internet from there. Two concrete consequences follow, and they are worth having.
- The local network stops seeing your traffic. Whoever runs the Wi-Fi you are on sees an encrypted stream to one address, not a list of the sites you visited.
- Your internet provider stops seeing it too. The destination list moves from your ISP to the VPN operator. That is a transfer of trust, not an elimination of it.
- Sites see the exit point’s address rather than yours. Useful if the specific thing you want is for a website not to learn your rough location from your IP address.
The coffee-shop scenario, revisited
The strongest VPN argument used to be the untrusted local network — someone on the same café Wi-Fi reading what you send. That argument has weakened considerably, and the FTC says why. "In the past, if you used a public Wi-Fi network to get online, your information was at risk." Now: "Today, most websites do use encryption to protect your information" and "connecting through a public Wi-Fi network is usually safe."
The transport encryption a VPN adds is, for most traffic, a second layer over one that is already there. That does not make it worthless — it does mean the scenario the marketing rests on is much less alarming than it was a decade ago, and the FTC’s article no longer recommends a VPN as the answer to it.
Four things it does not do
- It does not make you anonymous. The moment you sign into an account, that service knows exactly who you are. A tunnel changes the route, not the login.
- It does not stop tracking by sites you use. Cookies, advertising identifiers, fingerprinting and the profile a service builds from your own activity are unaffected. The FTC’s tracking controls — browser privacy settings, per-device ad opt-outs, the mobile advertising ID, app permissions — are all still the relevant tools.
- It does not protect against phishing or malware. A fraudulent site reached through a VPN is exactly as fraudulent. The FTC’s point that "your data may be encrypted on its way to the site, but it won’t be safe from scammers operating the site" applies with equal force to an encrypted tunnel.
- It does not cover traffic that leaves by another route. NCSC: "only traffic which is routed over the VPN will be protected by it", and third-party clients raise the risk that "some data may be sent outside the VPN" through poor operating-system integration.
When routing your traffic elsewhere is genuinely the right tool
There are cases where the narrow effect is precisely what you need. Reaching a private network — a work system, a home server — from somewhere else is the original purpose, and the one NCSC actually writes guidance for. Keeping the operator of a network you do not trust from seeing which sites you use is a legitimate reason. So is preventing a website from inferring your location from your address.
Notice that all three are specific and checkable. If you cannot state which of them you are buying, the honest answer is that you are buying reassurance.
Where NCSC does make a recommendation, it is about the standard rather than the supplier: IPsec, an open standard, with client certificates for machine authentication. That is a different kind of advice from a product ranking, and it is deliberately so.
Why the anonymity framing survives
Because it is easy to sell and hard to disprove from the sofa. Nothing visibly changes when you switch a VPN on, so the claim that everything is now protected meets no resistance. And the mechanism is genuinely opaque to most users, which leaves plenty of room for a bigger promise than the technology supports.
Set against the controls the agencies actually name — automatic updates, phishing-resistant authentication, careful reading of addresses, per-device privacy settings — a VPN is a modest supporting measure. Treating it as the centrepiece is where the harm lies, because the things it does not do are the things that actually happen to people.
Sources: NCSC UK — Virtual private networks · FTC — Are public Wi-Fi networks safe? · FTC — How to protect your privacy online · FBI IC3 — PSA I-061019 on the lock icon and HTTPS
Reviewed 27 August 2026 by the CyberArtical editorial team against primary guidance from NCSC UK, the FTC and the FBI. Security guidance changes over time; where our earlier version of this page said something different, we say so in the article rather than editing it out quietly.