ABOUTVPNS / FIELD NOTE 01
What a VPN Does - and Does Not Do
Understand the encrypted tunnel, who you still trust, and why a VPN is not an anonymity switch.
Follow the connection
A virtual private network creates a protected connection between endpoints across another network. With a typical personal VPN, your device connects to a provider's server, which sends traffic onward. With a work VPN, the destination may instead be a private business network. Start by asking where the tunnel ends: that boundary tells you which part of the journey it protects.
VPN and HTTPS do different jobs
HTTPS protects the connection between an application such as your browser and a website. A VPN protects traffic carried inside its tunnel. They can work together. The VPN endpoint does not automatically decrypt an HTTPS session, and the tunnel does not turn an unencrypted destination into an encrypted one. Keep HTTPS and certificate validation enabled.
Trust moves; it does not disappear
A local network generally sees the VPN connection, its timing and the amount of data, rather than the contents of traffic inside the tunnel. A VPN operator can have visibility into connection metadata and destinations; precisely what is visible depends on protocols and configuration. Logging into an account still identifies you to that service. Cookies, browser signals and information you submit are not erased by changing an exit IP.
A useful everyday example
Imagine using a personal laptop in a hotel. A VPN may protect the tunnel across that network, but it cannot recognize every fraudulent shopping page. If you willingly enter a card number on a dishonest site, the encrypted connection simply delivers it securely to the wrong party. Updates, account protection and checking the destination remain separate tasks.
Before you connect
Choose a defined purpose: protecting a network path, reaching work resources or testing a service you administer. Use an approved client from its official source. Check what happens when the tunnel disconnects and whether all intended applications use it. A connected icon is evidence of a connection, not a complete security assessment.
Sources and Further Reading
Sources support the technical concepts. Examples and checklists are our educational synthesis, not a provider review or a substitute for current deployment guidance.