VPN
Image: Ludovic.ferre (talk · contribs), CC BY-SA 4.0, Wikimedia Commons
In short: “Virtual Private Network” — an encrypted tunnel through an insecure network (usually the internet) that connects two networks, or a device and a network, as if they were directly cabled together.
In more detail: A VPN encrypts all traffic between client and VPN server, so that third parties on the network in between (e.g. public Wi-Fi) can’t read the content. Typical uses: remote access by employees to the company network, connecting several sites of a company (site-to-site VPN), or bypassing geographic blocks. Technically, a VPN is usually based on a tunnel protocol (e.g. WireGuard, OpenVPN, IPsec) combined with encryption.
In Depth
How a VPN changes your apparent location
From the perspective of the rest of the internet, a VPN changes WHERE a device appears to be located:
Without VPN: Device -> [public Wi-Fi, unprotected] -> destination server
(anyone on the same Wi-Fi can theoretically read along)
With VPN: Device -> [encrypted tunnel] -> VPN server -> destination server
(the destination only sees the VPN server's IP, not the real one)
Site-to-site vs. remote-access VPN
For companies, the most common use case is remote access (remote-access VPN): employees working from home connect to the company network via a VPN, so they can use internal systems (which are actually only reachable on the local company network) just as if they were physically sitting in the office — without these internal systems having to be directly and unprotectedly reachable from the entire internet. This is distinct from site-to-site VPN, where not a single device but two entire networks are permanently connected via a VPN tunnel — typically used to couple multiple company sites, or a data centre with a cloud environment, so that devices on both sides can reach each other as if they were on the same local network.
Comparing protocols
The specific choice of protocol has noticeable effects: OpenVPN is considered very mature and flexibly configurable, but has a comparatively large, complex codebase (over 100,000 lines), which increases the attack surface for vulnerabilities. WireGuard was deliberately kept radically simpler (under 4,000 lines of kernel code), uses modern, fixed cryptography algorithms instead of a configurable choice, and is now considered the preferred choice for new implementations because of its lower complexity, better auditability and higher speed. IPsec, in turn, is especially widespread in corporate networks, because it’s often directly integrated into network hardware (routers, firewalls) and is well suited for site-to-site connections between locations with fixed infrastructure.
Limits and the shift of trust
With commercial consumer VPN services (often advertised for privacy or geo-bypassing), an important point to consider is that the VPN merely shifts trust — instead of your own internet provider, you now have to trust the VPN provider, who could technically see all the traffic (even if reputable providers pursue a “no-logs” policy, which is however hardly independently verifiable from outside unless a regular external audit is published). A VPN doesn’t make anyone completely anonymous — the destination site you ultimately communicate with still sees who’s logged in, as soon as you sign in with your own name, VPN or not. For real anonymity (where even the network operator doesn’t know the destination site), you need other approaches such as the Tor network, which routes traffic through several independent, nested-encrypted relays instead of through a single central VPN provider.
VPN vs. proxy
A common misconception is equating a VPN with a simple proxy: a proxy only redirects the traffic of certain applications (often just the browser) and usually doesn’t add any encryption — a VPN, by contrast, works at the operating-system level, encrypts all traffic of all applications as a matter of principle, and routes it through the tunnel, regardless of which program establishes the connection.