A friend texted me last year saying he'd downloaded a VPN so he could "be completely anonymous online." He was using the free version of Hola VPN. I had to break some bad news to him.
This stuff comes up constantly. VPNs have been marketed so aggressively — by YouTubers, podcasters, random ads — that a huge chunk of people genuinely believe a VPN is some kind of invisibility cloak. It's not. And depending on how you're using it, it might be giving you a false sense of security that's actually dangerous.
Let me break down what's real and what's marketing fluff.
First, the one-line version of how a VPN works
A VPN creates an encrypted tunnel between your device and a VPN server. Your internet traffic goes through that server, so websites see the server's IP address instead of yours. Your ISP sees encrypted traffic going to the VPN server, but can't read what's inside.
That's it. That's the whole thing. Everything else flows from understanding those two effects: traffic encryption and IP masking.
Myth #1: A VPN makes you anonymous
This is the big one. And it's just not true.
A VPN hides your IP address from the sites you visit. That's genuinely useful. But anonymity requires a lot more than that. The moment you're logged into Google, Facebook, or your email — you've identified yourself. The VPN doesn't change that.
Google's tracking works through your account, cookies, browser fingerprinting, and device identifiers. A VPN does nothing to any of those. I ran a quick test last year using EFF's Cover Your Tracks tool (coveryourtracks.eff.org) while connected to Mullvad VPN. My browser fingerprint was still unique enough to identify me from millions of other users.
"VPNs shift trust from your ISP to your VPN provider. They don't eliminate it." — This is basically the honest version of every privacy engineer's take I've ever read.
Browser fingerprinting alone — combining your screen resolution, installed fonts, time zone, browser plugins, and GPU rendering — can identify you with over 90% accuracy according to a 2023 study from INRIA, even without any cookies. A VPN does zero about this.
If you want actual anonymity, you'd need Tor, a hardened browser like Tor Browser, zero accounts, and a lot of patience. A VPN is not that.
Myth #2: A VPN protects you from malware and hackers
Oh man. I see VPN ads lean into this one hard and it genuinely bothers me.
A VPN is not an antivirus. It's not a firewall. It doesn't inspect your downloads. It doesn't block malicious scripts running on a webpage you visit. If you click a phishing link and download ransomware, your VPN will happily encrypt that ransomware's traffic as it phones home to the attacker's command-and-control server.
Some VPN providers like NordVPN (with its Threat Protection feature) and Surfshark (CleanWeb) do offer DNS-based ad and malware blocking. That's a lightweight extra, not a replacement for actual endpoint security. It catches some known bad domains. It won't stop a zero-day exploit or a novel phishing page.
For real endpoint protection in 2026, you want something like Malwarebytes Premium (~$40/year), CrowdStrike Falcon Go, or at minimum Windows Defender with cloud protection turned on. A VPN sits in a completely different layer of your security setup.
Myth #3: Free VPNs are basically the same thing
Nope. Not even close.
I spent way too long back in 2019 figuring out why my browsing felt weird and why I kept seeing hyper-targeted ads even with a "privacy" VPN on. Turns out the free VPN I was using was injecting tracking cookies. That's a real thing that happened.
The infamous case: Hola VPN was caught in 2015 selling its users' bandwidth to form a botnet (via its subsidiary Luminati Networks, now called Bright Data). That's not ancient history — the business model is still out there in different forms. A 2019 analysis by Top10VPN found that of the top 150 free VPN apps on Google Play, 72 contained third-party tracking libraries.
If you want a trustworthy VPN, you're paying for it. Mullvad costs €5/month and accepts cash payments. ProtonVPN starts at $4.99/month and has been independently audited. IVPN is another solid audited option. These aren't sponsored mentions — I've actually run traffic tests through all three using Wireshark to verify their encryption claims held up.
Myth #4: A VPN protects you on public Wi-Fi from "hackers"
This one's complicated because it used to be more true than it is now.
Five or six years ago, public Wi-Fi was genuinely sketchy in specific ways — man-in-the-middle attacks on HTTP traffic, session hijacking, evil twin access points. A VPN helped a lot with those.
But here's the thing: as of 2026, over 95% of web traffic is encrypted via HTTPS/TLS (per Google's Transparency Report, which tracks Chrome traffic). That means most of what you do on public Wi-Fi is already encrypted end-to-end at the application layer. An attacker sitting on the same Starbucks network can see that you're visiting google.com. They can't read what you're actually doing there.
A VPN on public Wi-Fi still hides which sites you're visiting from someone monitoring the network. That's a real benefit, especially in countries where that metadata matters — Pakistan, UAE, Russia, Iran all have documented cases of ISP-level traffic monitoring. If you're traveling internationally, this is more meaningful than if you're just grabbing coffee in your home city.
The "hacker on public Wi-Fi" threat is real but narrower than the marketing suggests. It's not zero. It's just not the universal lifesaver it's positioned as.
What a VPN actually does well
I don't want this to read like a hit piece on VPNs. They're genuinely useful tools. Just for specific things.
Hiding your traffic from your ISP
Your internet provider can see every domain you visit. In the US, the 2017 repeal of FCC broadband privacy rules (under the Congressional Review Act, S.J.Res.34) means ISPs can legally sell your browsing history to advertisers. Comcast, AT&T, Verizon — they can and do monetize this data. A VPN stops that.
Same thing applies if you're at a workplace or school network. Your network admin can see your traffic. A VPN encrypts it from their view.
Bypassing geographic restrictions
This is obvious but it works. Accessing BBC iPlayer from outside the UK, getting different Netflix libraries, using services that are blocked in your country. A VPN is the standard tool for this and it does it well.
For people in countries with heavy internet censorship — China, North Korea, Belarus, Eritrea — a VPN with obfuscation (like Shadowsocks protocol support in ProtonVPN or Astrill) can be genuinely important. This isn't a streaming convenience thing. It's access to information.
Stopping price discrimination
Airlines and booking sites sometimes show different prices based on your location. Connecting through a VPN in a different country can surface cheaper fares. I've saved real money doing this — booking through a server in India for flights that showed significantly lower prices than through a US server. It doesn't always work, but it's worth checking.
The VPN provider trust problem nobody talks about enough
Here's something I think people skip over. When you use a VPN, you're not eliminating a surveillance point — you're moving it. Your ISP used to see your traffic. Now your VPN provider sees it instead.
So when ExpressVPN (now owned by Kape Technologies, a company with a sketchy adware history) says "we don't log," you're trusting a corporate claim. Mullvad has been independently audited by Cure53 and their no-log claims have held up. ProtonVPN is based in Switzerland with GDPR obligations and has been audited by SEC Consult. Those are meaningful differences.
In 2021, a server seized from DoubleVPN (a service popular with criminal groups) by Europol contained full logs of user activity — despite the service claiming to log nothing. The logs were right there. So "no log" claims matter a lot, and audits are how you verify them.
If the VPN is free and you haven't figured out how they're making money — you're probably the product.
Quick reference: what a VPN does and doesn't do
- Hides your IP from websites you visit — Yes ✓
- Encrypts traffic from your ISP — Yes ✓
- Bypasses geographic content blocks — Usually ✓
- Stops Google/Meta from tracking you — No ✗
- Protects against malware or phishing — No ✗
- Makes you anonymous — No ✗
- Protects you from data breaches — No ✗
- Stops browser fingerprinting — No ✗
- Secures your accounts from being compromised — No ✗
So should you use one?
Honestly, probably yes — but for the right reasons.
If you're concerned about your ISP selling your data, use a paid and audited VPN. If you travel frequently or live in a country with aggressive internet surveillance, it's pretty close to essential. If you're trying to access content from other regions, it's the easiest solution that exists.
But if you think a VPN is your whole privacy strategy? That's where people get into trouble. You still need strong unique passwords (use Bitwarden, it's free and open source). You still need 2FA on your important accounts. You still need to think before clicking links in emails. You still need to keep your software patched.
A VPN is one layer. A useful layer. Not a security solution by itself.
The best analogy I have: a VPN is like tinted windows on your car. People can't see inside easily. But it doesn't stop someone from breaking the window, stealing what's inside, or following you home. It's a single, specific protection — and knowing exactly what it does makes it a lot more valuable than just turning it on and assuming you're covered.
