VPN advertising tends to portray public Wi-Fi as a battlefield where hooded hackers steal your bank account. That picture is overblown. Yet a VPN does have genuine uses, just not the ones usually promoted.

Here is what a VPN actually does, what it does not do, and how to decide whether you need one.

What a VPN actually does

A VPN creates an encrypted tunnel between your device and a server belonging to the provider. All your internet traffic goes through that tunnel, then out to the internet from that server.

There are three practical consequences:

  • The Wi-Fi operator only sees that you connected to one VPN server, not the list of sites you opened.
  • The sites you visit see the VPN server's IP address, not your real one.
  • Traffic that is not already encrypted stays protected while inside the tunnel.

What a VPN does not do

This part rarely appears in promotional material.

A VPN does not make you anonymous

The moment you sign into an email or social media account, that service knows who you are, regardless of IP address. Cookies, browser fingerprinting, and behavioural patterns can still link your sessions.

A VPN does not protect against malware or phishing

An encrypted tunnel delivers a malicious file just as efficiently as a safe one. A phishing page opened through a VPN is still a phishing page.

A VPN does not remove trust, it moves it

You stop trusting the cafe's Wi-Fi operator, and start trusting the VPN provider. If that provider keeps logs and sells them, your situation is worse than before.

A VPN does not replace HTTPS

Once traffic leaves the VPN server, it travels the open internet again. HTTPS end-to-end encryption remains the layer that matters most.

The key point: if every site you visit already uses HTTPS, and nearly all do , then the content of your communications is already protected without a VPN. What a VPN adds is hiding where you went, not what you sent.

When a VPN is genuinely useful

SituationDoes a VPN help?Why
Working with internal company systemsVery muchAccess to the office network and centralised security policy
Frequently using hotel and airport Wi-FiYesReduces exposure to unfamiliar network operators
Not wanting the network operator to see your browsingYesThe destination is hidden from the local network
Journalists or researchers with sensitive sourcesYesAn additional layer against network observation
Accessing services while travelling abroadDependsCheck each service's terms
Reading the news at your regular cafeNot neededHTTPS is adequate
Avoiding malwareNoNot a VPN's function
Protection against phishingNoRequires vigilance and 2FA

Criteria for choosing a VPN provider

A log policy audited by a third party

A "no logs" claim is easy to write. What has value is an independent audit whose report is published, updated periodically, and carried out by a verifiable firm.

A clear business model

If you are not paying, some other mechanism funds the servers, the bandwidth, and the staff. On VPN services, that mechanism is most often user data.

Modern protocols

WireGuard and OpenVPN are mature and widely reviewed choices. Avoid services offering only old protocols such as PPTP.

A kill switch that works

This feature cuts the internet connection if the VPN tunnel drops, preventing traffic leaking without your knowledge. Test it yourself after subscribing.

Geographically relevant servers

For users in Indonesia, servers in Jakarta or Singapore give far better latency than servers in Europe or America.

Jurisdiction and corporate transparency

A company that states its address and ownership and publishes a transparency report is easier to hold accountable than an anonymous entity.

Alternatives and complements to a VPN

These steps give some of a VPN's benefit without a subscription:

  • Mobile data tethering. For high-value transactions or sensitive work, your own operator's mobile network is generally more controlled than an unfamiliar Wi-Fi.
  • Encrypted DNS (DoH/DoT). Hides domain name requests from the local network. Available free in modern browsers and operating systems.
  • HTTPS-Only Mode. Every major browser offers it; switch it on so the browser refuses to load unencrypted pages.
  • Two-factor authentication. The most effective protection per rupiah spent, because it blocks the biggest consequence of a password leak.

Three kinds of VPN that get confused

Commercial subscription VPNs

The most heavily advertised kind. Their purpose is hiding your activity from the local network and your internet provider, and changing the IP address destination sites see.

Corporate VPNs

Used to reach an organisation's internal resources. The focus is not personal privacy but ensuring only authorised devices can reach internal systems. If your workplace provides one, use it for all work done on unfamiliar networks.

A VPN you run yourself

A private server you manage, at home, or with a cloud provider. You need not trust any third party, but you carry the responsibility for maintaining and securing it. This suits technical users who understand the consequences.

Configuration mistakes that render a VPN useless

  • The kill switch is off. When the tunnel drops momentarily, traffic flows out unprotected and you never notice.
  • DNS leaks. Domain name requests still go to the local network's server, so the operator still sees which sites you open.
  • Split tunnelling set up wrongly. Apps that should be protected are excluded from the tunnel instead.
  • Turning the VPN on before completing the captive portal. The portal cannot load, and you conclude the network is broken.
  • Leaving old protocols enabled. Some apps still offer PPTP as a compatibility option.

After subscribing, take the time to test for DNS leaks and deliberately break the connection to confirm the kill switch works. An untested VPN gives a sense of safety that may not match reality.

The effect on speed, and how to reduce it

Every VPN adds two things: encryption and extra distance. Some ways to reduce the impact:

  • Choose the geographically nearest server, not whichever is automatically labelled "fastest".
  • Use a modern protocol such as WireGuard, which is lighter than its predecessors.
  • Switch off extra features such as multi-hop when they are not needed.
  • On older devices, encryption can burden the processor; consider turning the VPN on only when required.

Conclusion

A VPN is a useful tool for specific purposes: hiding where a connection is going from a network you do not trust, and reaching internal resources securely. It is not an all-purpose shield, and it does not replace basic habits such as keeping devices updated, using 2FA, and being careful with links.

If you only occasionally use cafe Wi-Fi to read and watch things, HTTPS already closes most of the risk. If you frequently move between unfamiliar networks carrying work data, a credible paid VPN is a reasonable investment.

Round it out with the 12 steps to public Wi-Fi safety and the guide to protecting personal data under the PDP Law.

Frequently asked questions

Does a VPN make me completely anonymous?

No. A VPN moves trust from the network operator to the VPN provider. You can still be identified through the accounts you sign into, browser cookies, and device fingerprinting.

Are free VPNs safe to use?

Most are not advisable. Running VPN infrastructure is expensive, so free services frequently fund themselves by selling user data or inserting ads. If budget is tight, the cheapest paid service is usually safer.

Does a VPN slow the internet down?

Generally yes, by 5 to 30 per cent, depending on server distance and the protocol used. Choosing a domestic server and a modern protocol such as WireGuard minimises the impact.

Is using a VPN legal in Indonesia?

Using a VPN for privacy and security is not prohibited. What remains subject to the law is what you do through it, a VPN does not change the legal status of an act.