VPN advertising is remarkably confident.
A virtual private network is often presented as the answer to almost every online concern: privacy, anonymity, hackers, tracking, public Wi-Fi, streaming restrictions, identity theft and even slow internet connections.
Some adverts make it sound as though pressing one button transforms an ordinary laptop into an invisible digital submarine.
The reality is more useful—but considerably less magical.
A properly designed VPN can encrypt the connection between your device and a VPN server, conceal your normal public internet address from the websites you visit and reduce what your internet provider or local network can see about your browsing destinations.
Those are genuine benefits.
However, a VPN does not make you anonymous, prevent websites identifying your accounts, remove cookies, block every tracker, stop phishing, clean malware from a computer or make a fraudulent website safe.
At Computer Repair Norwich, we regularly encounter VPN applications and browser extensions installed because an advert promised “complete protection”. Sometimes the VPN is legitimate but misunderstood. In other cases, a questionable free service has introduced advertising, changed browser settings, affected network performance or created a new privacy concern of its own.
This guide explains what VPNs really do, what they cannot do, which claims are myths and when using one makes practical sense.
You can find our other plain-English technology guides in the Computer Repair Advice Norwich section.
What does VPN mean?
VPN stands for Virtual Private Network.
The term originally described technology used to connect computers or separate locations securely across another network, such as the public internet.
A business might use a VPN to allow someone working from home to access internal files, systems or services as though their computer were connected directly to the office network.
Commercial consumer VPNs use similar tunnelling principles for a different purpose. Instead of connecting you primarily to an employer’s internal network, they send some or all of your internet traffic through a server operated by the VPN provider.
The UK National Cyber Security Centre describes VPNs as encrypted network connections that can provide secure connectivity between physically separate devices and services. It also stresses that only traffic actually routed through the VPN receives that protection.
How a consumer VPN works
Without a VPN, your connection usually follows a route broadly like this:
Your device → router or local network → internet provider → destination website
When a VPN is active, the route becomes:
Your device → encrypted VPN tunnel → VPN server → destination website
The VPN application creates an encrypted connection between your device and the VPN provider’s server.
Someone monitoring the local Wi-Fi network or your internet connection should be able to see that your device is exchanging data with a VPN service, but they should not receive the same clear picture of the final websites and services being reached through that tunnel.
Once the traffic reaches the VPN server, it is forwarded towards the destination.
The website normally sees the public internet address of the VPN server rather than the address assigned to your home, business or mobile connection.
This is why a VPN can make a website think your connection is coming from another city or country.
The Federal Trade Commission explains that VPN applications route device traffic through servers controlled by the provider and may encrypt information travelling between the device and that server. It also warns that using a VPN places considerable trust in the company operating it.
Where does the VPN encryption end?
This is an important detail that VPN marketing frequently glides past.
The special VPN tunnel normally protects the connection between your device and the VPN server.
Once the traffic leaves that server, the VPN tunnel has ended.
For modern HTTPS websites, the browser also creates its own encrypted connection with the website. That HTTPS protection continues between your browser and the website, including across the VPN server.
This means the VPN provider may be able to observe connection information such as which servers are being contacted, depending on the service’s design and the technologies in use, but it should not simply be able to read the contents of properly encrypted HTTPS pages.
For an unencrypted connection, the situation is less reassuring. Traffic leaving the VPN server without separate encryption may potentially be visible to networks between that server and its destination.
A VPN should therefore complement HTTPS, not replace it.
What a VPN can genuinely do
Hide your normal public internet address from websites
When the VPN is working correctly, websites normally receive the address of the VPN server rather than your home or mobile internet address.
This can reduce the ability of websites and advertising systems to use your normal address as part of a tracking profile.
However, an internet address is only one of many ways a user can be recognised.
Cookies, account logins, browser fingerprinting, advertising identifiers and information you enter yourself can still identify or distinguish you.
Reduce what your internet provider can see
Your internet provider must still carry the encrypted VPN connection and will normally know that you are using a VPN.
It may also see when you connected, how long the connection lasted and approximately how much data was transferred.
However, it should not receive the same direct view of the individual destinations being accessed through a properly configured encrypted tunnel.
The important catch is that this visibility has not simply vanished. Some of it has moved from the internet provider to the VPN provider.
A VPN is therefore partly a decision about who you trust with your connection.
Protect traffic on an untrusted local network
A VPN can provide an additional layer of protection when using hotel, airport, café or other shared Wi-Fi.
People operating or monitoring the local network should see an encrypted connection to the VPN server rather than the individual services being reached through it.
This is particularly valuable for business systems, specialist services or applications that may not protect their own traffic adequately.
However, public Wi-Fi is not quite the lawless wilderness it once was. Most mainstream websites and applications now use HTTPS encryption, and the FTC says that widespread HTTPS adoption means connecting through public Wi-Fi is usually safer than it was historically. A VPN can still add protection, but claims that using any public hotspot without one means instant catastrophe are outdated.
Provide secure access to a business network
This remains one of the clearest uses for VPN technology.
A company VPN can allow authorised staff to reach internal systems without exposing those systems directly to the public internet.
The VPN does not automatically make the connected computer trustworthy. The device still needs updates, appropriate security, strong authentication and protection from malware.
A compromised home computer connected to a business VPN may provide an attacker with a route towards company resources. The tunnel can be secure while the device at one end is not.
Change the apparent location of your connection
Many commercial VPN providers operate servers in several countries.
Connecting through one of those servers can make websites see the VPN server’s region rather than your normal location.
This may be useful when:
- travelling and accessing services that behave differently abroad
- testing how a website appears in another country
- avoiding basic location assumptions based on an internet address
- connecting from a network where certain services are unavailable
- accessing information restricted by a local network
It does not guarantee access to every service. Websites can recognise and block known VPN servers, request additional verification or use other location information from accounts, devices and payment methods.
Changing an apparent internet location also does not change the law, contractual terms or access rules applying to a service.
Reduce some forms of network-level profiling
Because many customers share the same VPN server address, it can be harder to connect activity to one household using that address alone.
This is useful, but it should not be confused with complete anonymity.
The website may still recognise the same browser, cookies, account, device characteristics or advertising identifiers.
What a VPN cannot do
A VPN does not make you anonymous
This is the largest and most persistent myth.
A VPN changes the network route and the address visible to destination websites. It does not erase everything else that identifies you.
You can still be recognised when you:
- log into an email or social-media account
- use an existing browser profile
- retain tracking cookies
- allow browser fingerprinting
- enter your name or address
- make a payment
- use a recognisable username
- share your location
- stay signed into Google, Microsoft, Apple or another service
- use applications containing persistent advertising identifiers
The Electronic Frontier Foundation states plainly that a VPN is not an anonymity tool and that companies can still track users through GPS information, cookies, tracking pixels and browser fingerprinting.
A VPN may improve privacy in a particular part of the connection. That is not the same as becoming anonymous.
A VPN does not stop cookies or browser fingerprinting
Cookies are stored in the browser and can identify a returning session even when the internet address changes.
Browser fingerprinting combines characteristics such as screen dimensions, fonts, operating system, graphics capabilities, language, time zone and browser features.
A VPN does not automatically alter those characteristics.
Privacy-focused browsers and tracker-blocking tools address different parts of the problem. Our guide to DuckDuckGo private search and browser protection explains how search privacy and tracker blocking differ from a VPN connection.
A VPN does not protect you from phishing
A fake banking page remains fake when reached through an encrypted VPN tunnel.
If you enter a password, card number or security code into a fraudulent website, the VPN will securely deliver that information to the scammer.
The connection can be encrypted perfectly while the destination is completely dishonest.
Our guide to phishing emails, fake virus warnings and scam messages explains the warning signs that a VPN cannot detect on your behalf.
A VPN does not remove malware
A VPN is not an antivirus program or malware-cleaning tool.
It cannot repair:
- an infected operating system
- a malicious browser extension
- password-stealing malware
- a remote-access infection
- ransomware
- browser hijacking
- an unsafe downloaded program
- commands already executed through PowerShell or Windows Run
Some VPN products include separate malicious-site blocking, advertising filters or security features. Those additions may be useful, but they are not inherent to VPN technology.
If the device is already compromised, the malware can continue operating through the VPN connection.
This is particularly relevant to fake verification attacks. Our fake CAPTCHA and ClickFix warning explains how websites can trick users into manually running malicious commands.
A VPN does not make unsafe downloads safe
Files do not become trustworthy because they were downloaded privately.
A fake installer, pirated application, malicious attachment or infected document can still harm the device after it arrives.
The VPN protects the journey. It does not inspect the passenger’s intentions.
A VPN does not secure weak passwords
A weak or reused password remains weak.
If an attacker obtains it through a data breach, phishing page, malware infection or reused credentials from another account, a VPN does not prevent that attacker logging in.
Strong unique passwords and two-step verification protect a different layer of security.
A VPN does not stop websites seeing what you provide
When you submit a delivery address, email address, payment card or personal message, the website receives it.
A VPN may hide the normal internet address from which the connection originated, but it cannot make information voluntarily submitted to the service disappear.
A VPN does not hide everything from an employer
A personal VPN may reduce what the local network can observe, but activity performed through company accounts, managed devices and business applications can still be logged by those services.
On an employer-owned computer, monitoring software, browser policies, security agents and device-management systems may operate directly on the machine before traffic enters the VPN.
When using a company VPN, the business may intentionally route and monitor traffic for security and compliance.
A VPN should not be treated as a way to override workplace policies.
A VPN does not guarantee that your location is hidden
Websites and applications can estimate or learn location through:
- GPS permissions
- nearby Wi-Fi information
- mobile-network data
- account history
- billing details
- delivery addresses
- browser settings
- previous sessions
- device-location services
Changing the internet address alone may not overcome these other signals.
A VPN does not automatically improve internet speed
Encryption, extra routing and the distance to the VPN server usually add some overhead.
Performance depends on:
- the VPN provider’s capacity
- server congestion
- physical distance
- the chosen protocol
- the device’s processor
- the original internet connection
- the quality of the route
- whether the provider limits speed
In unusual cases, a VPN can produce a better route or avoid a particular type of traffic management, making one service feel faster.
That is the exception, not the primary purpose.
A VPN should not be sold as a general repair for slow broadband.
Myth: “Nobody can see what I do when the VPN is on”
Your internet provider may see less detail about destinations reached through the tunnel.
The websites you use still see what you do on those websites.
The VPN provider operates the server through which your traffic passes and may potentially see connection information. Exactly what it can observe or retain depends on its technical design, privacy practices and the separate encryption used by the applications and websites involved.
Account providers can still record logins, searches, purchases and activity attached to those accounts.
Malware installed on the device can potentially observe activity before it enters the VPN tunnel.
“Nobody can see anything” is therefore impossible as a general statement.
Myth: “A no-logs claim means nothing is recorded”
A no-logs policy can be valuable, but the words alone are not proof.
Providers use “no logs” to mean different things.
One company may mean it does not store browsing destinations. Another may still retain connection times, device information, server selections, bandwidth usage, account details or diagnostic records.
Some information may also be processed temporarily for operating the service even when it is not retained long-term.
Independent audits can provide useful evidence, but an audit normally examines a particular system, scope and point in time. It does not turn future marketing claims into an eternal guarantee.
Before choosing a provider, read what it says it collects—not merely the sentence printed in the largest font.
Myth: “Free VPNs provide the same thing without the bill”
Operating servers, developing applications, providing bandwidth, handling abuse and maintaining security costs money.
A free service must still be funded somehow.
Possible models include:
- a limited free tier supporting a paid service
- advertising
- data collection
- commercial partnerships
- restricted speed or bandwidth
- fewer server locations
- in-app promotions
- selling another product
- redirecting or analysing traffic
A free VPN is not automatically dishonest, and a paid VPN is not automatically trustworthy.
However, unexplained free services deserve particular caution because a VPN receives unusually powerful access to network traffic.
The FTC warns that some VPN applications have failed to encrypt traffic properly, requested unexpected permissions or shared information with third parties.
Myth: “The VPN company cannot see anything”
A VPN provider may not be able to read the protected contents of properly encrypted HTTPS sessions, but it still operates an important part of the connection.
Depending on the service and configuration, it may be able to observe:
- your original internet address
- connection times
- the server selected
- the amount of data transferred
- destination addresses or related network metadata
- account and payment information
- application diagnostics
- unencrypted traffic
This does not mean every provider records or misuses that information.
It means the service must be chosen on trust, supported by transparent policies, sound technology and credible evidence.
Myth: “A VPN blocks viruses”
A VPN can sometimes block known malicious domains if the provider includes a separate filtering service.
That is an optional feature, not the VPN tunnel itself.
It does not examine every file intelligently, reverse actions already performed or guarantee that a newly created phishing page will be recognised.
Security still depends on:
- keeping the operating system updated
- maintaining current browsers and applications
- using reputable security software
- checking links and downloads
- protecting accounts
- avoiding suspicious extensions
- responding properly when something goes wrong
Myth: “HTTPS makes a VPN completely pointless”
HTTPS and VPNs protect different parts of the route.
HTTPS encrypts the connection between an application or browser and the destination service.
A VPN encrypts traffic between the device and the VPN server while also changing the internet address visible to destinations.
Because HTTPS is now widespread, a VPN is no longer essential merely to stop someone in a coffee shop casually reading the contents of mainstream encrypted websites.
A VPN can still:
- conceal destination information from the local network and internet provider
- cover applications whose traffic might otherwise be exposed
- provide access to private business systems
- change the apparent internet location
- apply one encrypted tunnel across several applications
- add protection where the underlying service is poorly configured
The sensible answer is not “HTTPS makes VPNs useless” or “public Wi-Fi without a VPN is suicidal”.
It depends on the network, application, threat and reason for connecting.
Myth: “Incognito mode does the same thing”
Private or incognito browsing mainly controls what the browser retains locally after the private window closes.
It may avoid keeping ordinary browsing history, cookies and form information in the usual profile.
It does not normally hide your internet address from websites or create an encrypted tunnel through another server.
A VPN changes the network route.
Private browsing changes local browser behaviour.
They solve different problems and can be used together.
Myth: “Tor Browser is just a free VPN”
Tor and commercial VPNs both alter the route between a user and the destination, but their designs differ substantially.
A typical VPN sends traffic through one provider’s server. The provider knows the original connection and controls the server forwarding the traffic.
Tor Browser routes browsing through several relays operated by different participants. Its design attempts to prevent one relay from knowing both the user’s original address and final destination.
Tor is generally slower and can trigger more website restrictions. It also focuses on browser anonymity rather than routing every application on the device by default.
Our guide to Tor Browser, onion routing and its limitations explains the distinction.
Neither tool eliminates the need to behave carefully or understand what information you reveal.
Full VPN, browser VPN or proxy?
Not every product labelled “VPN” protects the same traffic.
Full-device VPN
A conventional VPN application can route most or all network traffic from the device through its tunnel.
This may include browsers, email programs, cloud applications and other software.
Browser extension
Some browser extensions called VPNs operate only inside that browser.
Other applications on the computer continue using the ordinary connection.
Some extensions are technically encrypted proxies rather than full VPN services. That does not automatically make them useless, but the distinction should be clear.
Split tunnelling
Split tunnelling allows selected applications or destinations to use the VPN while others bypass it.
This can be useful when:
- a local printer or network device must remain accessible
- only one application needs the VPN
- streaming or gaming should use the normal connection
- business traffic must go through the company network
- reducing VPN bandwidth is important
It also means traffic intentionally excluded from the tunnel does not receive its protection.
The NCSC warns that only routed traffic is protected and discusses the security difference between optional and forced VPN configurations.
What is a VPN kill switch?
A kill switch is designed to stop network traffic if the VPN connection unexpectedly drops.
Without one, the computer may quietly return to its normal connection while the user assumes the VPN is still active.
A reliable kill switch is particularly important when revealing the normal internet address would create a genuine privacy or security risk.
It can also cause apparent internet faults. If the VPN application crashes, becomes corrupted or fails to connect, the kill switch may continue blocking traffic until the VPN is repaired or disabled properly.
This is one reason a computer can appear to have “lost the internet” even though the broadband connection itself is working.
What are DNS leaks?
The Domain Name System converts names such as a website address into the numerical network information required to reach the service.
A VPN will usually provide or route DNS requests through its own selected service.
A DNS leak occurs when those requests bypass the intended VPN route and continue using another DNS provider, potentially revealing destination information outside the tunnel.
The significance depends on what the user is trying to protect and what other encrypted DNS technology is in use.
DNS, IPv6, split-tunnelling and kill-switch behaviour are reasons to test a VPN rather than assume the connected symbol means every piece of traffic is following the expected route.
How to choose a VPN provider
We do not think one provider is automatically right for every CRN customer.
The correct choice depends on why the VPN is needed.
Before installing one, check:
Who owns and operates it?
Look beyond the product name.
Several apparently competing VPN brands can belong to the same parent company. Ownership, management and business history matter when a service is being trusted with network traffic.
What information does it collect?
Read the privacy policy carefully.
Look for specific explanations covering:
- original internet addresses
- connection timestamps
- browsing destinations
- bandwidth records
- device identifiers
- crash reports
- account details
- payment information
- advertising data
- third-party sharing
“Privacy first” is a slogan. A clear description of actual data handling is evidence.
How is it funded?
A subscription model is easy to understand, though payment does not guarantee honesty.
For a free service, establish what supports it and whether the free product exists as a limited introduction to a reputable paid service.
Does it use established protocols?
Common modern VPN protocols include WireGuard, OpenVPN and IKEv2.
A provider should explain what it uses rather than hiding everything behind words such as “military-grade protection”.
Encryption can be technically strong while the application, company or privacy policy remains poor.
Does it include a kill switch?
Check whether the feature is available on the operating system you intend to use and whether it is enabled automatically.
Does it support the devices you actually own?
A service may support Windows and Android while offering fewer features on macOS, iPhone, Linux, routers or smart televisions.
Check whether the same privacy and security features exist on each platform.
Has it been independently audited?
A credible external audit can improve confidence, particularly when the report or a meaningful summary is published.
Check:
- who performed the audit
- what systems were examined
- when it happened
- what was excluded
- whether problems were corrected
Does it have a clear security history?
Security incidents do not automatically prove a provider is permanently unsafe. Every substantial service can encounter vulnerabilities.
The response matters.
Look for transparent disclosure, prompt correction and evidence that lessons were applied.
Does it make impossible promises?
Treat claims such as these with suspicion:
- completely anonymous
- impossible to track
- protects against every hacker
- prevents all viruses
- guarantees access to every streaming service
- makes any Wi-Fi completely safe
- stores absolutely nothing under any circumstances
- cannot ever be compromised
The EFF advises users to be wary of exaggerated VPN privacy and security claims.
When a VPN makes sense
A VPN can be a sensible tool when:
- an employer requires secure remote access
- you regularly use shared or untrusted networks
- you want to reduce what your internet provider can learn about destinations
- you want websites to see a shared VPN address rather than your usual address
- you need secure access to systems in another physical location
- you are travelling and need your connection to appear in a familiar region
- a particular application lacks suitable protection on its own
- you understand and trust the provider handling the connection
When a VPN may not be necessary
A consumer VPN may add little value when:
- you only expect it to make you anonymous
- the main concern is phishing or malware
- you already use secure updated devices and HTTPS services on a trusted network
- you remain signed into identifying accounts throughout every browsing session
- you intend to choose an unknown free service without researching it
- the application creates more instability than the privacy benefit justifies
- you are trying to repair a slow or infected computer
- your employer already provides a managed secure connection
- the service you need repeatedly blocks VPN servers
It is perfectly reasonable to decide that a VPN does not solve the problem you actually have.
Security software should be chosen because it addresses a defined risk, not because a countdown timer says the 83% discount expires before you finish reading the sentence.
VPN problems we see at Computer Repair Norwich
VPN software can create or expose several computer problems.
These include:
- no internet connection after the VPN disconnects
- a kill switch continuing to block traffic
- damaged virtual network adapters
- DNS settings that do not restore correctly
- slow connections through overloaded servers
- browser extensions changing search or homepage settings
- conflicts with antivirus or firewall software
- a corporate VPN failing after a Windows update
- login loops or repeated authentication errors
- local printers and network devices becoming unavailable
- unknown free VPN applications displaying advertising
- proxy settings left enabled after uninstallation
- several VPN products installed at the same time
Sometimes reinstalling or correctly removing the VPN solves the problem.
In other cases, the VPN is merely where the fault becomes visible. The underlying cause may be Windows corruption, malware, failing storage, an unstable wireless adapter or security software interfering with the connection.
How VPNs relate to Computer Repair Norwich
A VPN can improve one part of online privacy, but it cannot substitute for a healthy and secure computer.
At Computer Repair Norwich, we can help when a VPN, browser extension or network-security application has caused:
- lost internet access
- extremely slow browsing
- unwanted pop-ups
- changed proxy or DNS settings
- suspicious browser behaviour
- repeated connection errors
- software conflicts
- concerns about an unknown VPN application
- possible malware or account compromise
Our Virus and Malware Removal Norwich service covers unwanted applications, malicious browser extensions, redirects, suspicious remote-access tools and possible infections.
If the computer stopped connecting after a VPN was installed or removed, or you are unsure whether a privacy application is legitimate, contact Computer Repair Norwich to arrange an inspection.
A VPN can be useful when it is solving the right problem.
The first step is knowing what that problem actually is.

