Home/Answers/Privacy

Privacy · Plain-English answer

HTTPS vs VPN: what is the difference?

HTTPS encrypts the content between your browser and one website, while a VPN encrypts all traffic from your device and hides your IP address. HTTPS stops anyone reading what you send to a site, but observers still see which sites you visit. They are complementary layers, not alternatives.

What HTTPS covers

The padlock in your browser means traffic between you and that specific site is encrypted. Passwords, card numbers, and page contents cannot be read or altered in transit, which is why online banking was safe long before VPNs were mainstream. Most of the web uses HTTPS today.

What HTTPS does not hide is the metadata. Your ISP and network still see which domains you connect to, when, and how much data flows, and the website still sees your real IP address.

What a VPN adds on top

A VPN wraps everything, including the HTTPS traffic, in another layer of encryption to its server. That hides the list of sites you visit from your ISP and local network, covers apps and services that are not websites, and replaces your IP address with the server's.

The right mental model is layers. HTTPS protects the content of each conversation, the VPN protects who you are talking to and where you are connecting from. Using ROOT VPN does not replace HTTPS, it runs alongside it, and you lose nothing by having both.

Related questions

If HTTPS encrypts everything, why bother with a VPN?
Because HTTPS hides content but not destinations. Your ISP still sees every domain you visit and sites still see your IP. A VPN hides both.
Does a VPN make HTTP sites safe?
Partly. It protects the leg between you and the VPN server. Beyond the server, unencrypted HTTP travels in the clear, so a VPN is not a full substitute for the site using HTTPS.

Keep reading

More from the ROOT VPN answers hub.

Private in one tap.

ROOT VPN is free to start with unlimited data, no card needed, and no activity logs.

Get ROOT VPN, free