«HTTPS is everywhere — so why a VPN?» It's a fair question: both encrypt. But they encrypt different things, on different stretches of the path.
The short answer
HTTPS protects the content of your conversation with a specific website along the entire path to it. A VPN protects all of a device's traffic, but only up to the VPN server. These are perpendicular things, and one doesn't replace the other.
What HTTPS does
It encrypts data between your browser and the website. No one along the way — not your ISP, not the Wi-Fi owner, not the VPN service — can read what you sent and received. Plus it confirms the site's authenticity with a certificate.
What it doesn't do: it doesn't hide which website you accessed. The domain name is transmitted in the open at the start of the connection, and name-service queries usually go separately.
What a VPN does
It encrypts all of a device's traffic — browser, apps, background services — and routes it through a server. Your network sees only the connection to that server.
What it doesn't do: it doesn't protect the stretch from the VPN server to the website. There everything depends on whether HTTPS is used.
Who sees what
| Situation | ISP sees | Website sees |
|---|---|---|
| No HTTPS, no VPN | Site name and content | Your IP |
| HTTPS without VPN | Site name; content — no | Your IP |
| VPN without HTTPS | Only the connection to the VPN | Server IP; content is visible on the server–site stretch |
| HTTPS + VPN | Only the connection to the VPN | Server IP, content encrypted |
Why «HTTPS is enough» isn't always true
Test it on your own device
8 hours free, no card required. Full access to all servers.
HTTPS covers content well, but leaves the list of addresses open. For an ISP that's enough to build a picture of your interests: which sites, when, how often. A VPN covers exactly this layer.
Why «a VPN is enough» isn't true either
After the VPN server, traffic goes into the regular internet. If a site works without HTTPS, the content is exposed again on that stretch. A VPN moves the point of risk rather than removing it.
The practical takeaway
HTTPS works on its own; you don't need to turn it on — just watch that there's no insecure-connection warning in the address bar. A VPN is turned on when you need to hide the list of addresses from the network, you're on someone else's Wi-Fi, or a service is unavailable from your network. Together they cover different layers, and that's exactly how you should think of them.