this post was submitted on 23 Dec 2025
160 points (96.5% liked)
Technology
77899 readers
3300 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Your internet traffic is already encrypted in transit, that what the "s" in https means.
A VPN does exactly two things: Hides your traffic from your ISP (but shows it to the VPN provider instead) and masks your IP and physical location.
Everything else is advertising and marketing gimmicks
You don't get the "s" until you have the "https". Your DNS request which turns www.TheWebsiteYouDoNotWantKnown.com into its IP address happens before you have the "s" in "https". By default, that request is sent in plaintext, and frequently by default, to your internet service provider. So an outside monitor may not be able to see the contents of the website once you establish your https connection, they likely know that you went there and have a good idea how long you stayed on it.
While its also possible to encrypt the DNS request with DoH or DoT, its not on by default and requires the user to take configuration actions in their browser. If they're looking at VPNs for the first time, they likely don't know this and are sending their DNS requests in the clear.
VPN also hides unencrypted DNS and non-browser traffic which are sometimes not TLS.