VPN advertising tends to portray public Wi-Fi as a battlefield where hooded hackers steal your bank account. That picture is overblown. Yet a VPN does have genuine uses, just not the ones usually promoted.
Here is what a VPN actually does, what it does not do, and how to decide whether you need one.
What a VPN actually does
A VPN creates an encrypted tunnel between your device and a server belonging to the provider. All your internet traffic goes through that tunnel, then out to the internet from that server.
There are three practical consequences:
- The Wi-Fi operator only sees that you connected to one VPN server, not the list of sites you opened.
- The sites you visit see the VPN server's IP address, not your real one.
- Traffic that is not already encrypted stays protected while inside the tunnel.
What a VPN does not do
This part rarely appears in promotional material.
A VPN does not make you anonymous
The moment you sign into an email or social media account, that service knows who you are, regardless of IP address. Cookies, browser fingerprinting, and behavioural patterns can still link your sessions.
A VPN does not protect against malware or phishing
An encrypted tunnel delivers a malicious file just as efficiently as a safe one. A phishing page opened through a VPN is still a phishing page.
A VPN does not remove trust, it moves it
You stop trusting the cafe's Wi-Fi operator, and start trusting the VPN provider. If that provider keeps logs and sells them, your situation is worse than before.
A VPN does not replace HTTPS
Once traffic leaves the VPN server, it travels the open internet again. HTTPS end-to-end encryption remains the layer that matters most.
The key point: if every site you visit already uses HTTPS, and nearly all do , then the content of your communications is already protected without a VPN. What a VPN adds is hiding where you went, not what you sent.
When a VPN is genuinely useful
| Situation | Does a VPN help? | Why |
|---|---|---|
| Working with internal company systems | Very much | Access to the office network and centralised security policy |
| Frequently using hotel and airport Wi-Fi | Yes | Reduces exposure to unfamiliar network operators |
| Not wanting the network operator to see your browsing | Yes | The destination is hidden from the local network |
| Journalists or researchers with sensitive sources | Yes | An additional layer against network observation |
| Accessing services while travelling abroad | Depends | Check each service's terms |
| Reading the news at your regular cafe | Not needed | HTTPS is adequate |
| Avoiding malware | No | Not a VPN's function |
| Protection against phishing | No | Requires vigilance and 2FA |
Criteria for choosing a VPN provider
A log policy audited by a third party
A "no logs" claim is easy to write. What has value is an independent audit whose report is published, updated periodically, and carried out by a verifiable firm.
A clear business model
If you are not paying, some other mechanism funds the servers, the bandwidth, and the staff. On VPN services, that mechanism is most often user data.
Modern protocols
WireGuard and OpenVPN are mature and widely reviewed choices. Avoid services offering only old protocols such as PPTP.
A kill switch that works
This feature cuts the internet connection if the VPN tunnel drops, preventing traffic leaking without your knowledge. Test it yourself after subscribing.
Geographically relevant servers
For users in Indonesia, servers in Jakarta or Singapore give far better latency than servers in Europe or America.
Jurisdiction and corporate transparency
A company that states its address and ownership and publishes a transparency report is easier to hold accountable than an anonymous entity.
Alternatives and complements to a VPN
These steps give some of a VPN's benefit without a subscription:
- Mobile data tethering. For high-value transactions or sensitive work, your own operator's mobile network is generally more controlled than an unfamiliar Wi-Fi.
- Encrypted DNS (DoH/DoT). Hides domain name requests from the local network. Available free in modern browsers and operating systems.
- HTTPS-Only Mode. Every major browser offers it; switch it on so the browser refuses to load unencrypted pages.
- Two-factor authentication. The most effective protection per rupiah spent, because it blocks the biggest consequence of a password leak.
Three kinds of VPN that get confused
Commercial subscription VPNs
The most heavily advertised kind. Their purpose is hiding your activity from the local network and your internet provider, and changing the IP address destination sites see.
Corporate VPNs
Used to reach an organisation's internal resources. The focus is not personal privacy but ensuring only authorised devices can reach internal systems. If your workplace provides one, use it for all work done on unfamiliar networks.
A VPN you run yourself
A private server you manage, at home, or with a cloud provider. You need not trust any third party, but you carry the responsibility for maintaining and securing it. This suits technical users who understand the consequences.
Configuration mistakes that render a VPN useless
- The kill switch is off. When the tunnel drops momentarily, traffic flows out unprotected and you never notice.
- DNS leaks. Domain name requests still go to the local network's server, so the operator still sees which sites you open.
- Split tunnelling set up wrongly. Apps that should be protected are excluded from the tunnel instead.
- Turning the VPN on before completing the captive portal. The portal cannot load, and you conclude the network is broken.
- Leaving old protocols enabled. Some apps still offer PPTP as a compatibility option.
After subscribing, take the time to test for DNS leaks and deliberately break the connection to confirm the kill switch works. An untested VPN gives a sense of safety that may not match reality.
The effect on speed, and how to reduce it
Every VPN adds two things: encryption and extra distance. Some ways to reduce the impact:
- Choose the geographically nearest server, not whichever is automatically labelled "fastest".
- Use a modern protocol such as WireGuard, which is lighter than its predecessors.
- Switch off extra features such as multi-hop when they are not needed.
- On older devices, encryption can burden the processor; consider turning the VPN on only when required.
Conclusion
A VPN is a useful tool for specific purposes: hiding where a connection is going from a network you do not trust, and reaching internal resources securely. It is not an all-purpose shield, and it does not replace basic habits such as keeping devices updated, using 2FA, and being careful with links.
If you only occasionally use cafe Wi-Fi to read and watch things, HTTPS already closes most of the risk. If you frequently move between unfamiliar networks carrying work data, a credible paid VPN is a reasonable investment.
Round it out with the 12 steps to public Wi-Fi safety and the guide to protecting personal data under the PDP Law.
Frequently asked questions
Does a VPN make me completely anonymous?
No. A VPN moves trust from the network operator to the VPN provider. You can still be identified through the accounts you sign into, browser cookies, and device fingerprinting.
Are free VPNs safe to use?
Most are not advisable. Running VPN infrastructure is expensive, so free services frequently fund themselves by selling user data or inserting ads. If budget is tight, the cheapest paid service is usually safer.
Does a VPN slow the internet down?
Generally yes, by 5 to 30 per cent, depending on server distance and the protocol used. Choosing a domestic server and a modern protocol such as WireGuard minimises the impact.
Is using a VPN legal in Indonesia?
Using a VPN for privacy and security is not prohibited. What remains subject to the law is what you do through it, a VPN does not change the legal status of an act.