"I've got HTTPS, the padlock's green, what else is there" is a common assumption. HTTPS covers a lot — just not everything a network you're connected to can see.
The DNS request: the first step that's often unprotected
Before opening a site, a device asks a DNS server which IP address matches that domain name. If that request goes out unencrypted — which, by default, it often does — the network sees the domain name before the HTTPS connection itself even begins.
This happens for every single site you open in a session — DNS requests build a fairly precise picture of what you're using, even when each individual page's content is fully encrypted.
SNI: a hostname sent in the clear, even over HTTPS
At the start of an HTTPS connection, the browser sends the server a field called SNI (Server Name Indication) — the hostname it's connecting to. This lets the server know which certificate to present when multiple sites share one IP address.
For historical reasons, SNI is sent unencrypted in a classic TLS handshake. So the network sees the hostname, even though the page's content is fully encrypted from that point on.
Metadata: volume and timing
Even without reading content, a network sees how much data moved, how long a connection stayed open, and how often. That's often enough to distinguish, say, a video call from a text conversation — from the traffic pattern alone, not the content.
What's unprotected if a site skips HTTPS entirely
A minority of sites still serve some content over plain HTTP. In that case, the network — and anyone technically positioned to listen in on it — sees the page's content outright: text, images, form data, unless it's protected some other way.
What changes with a VPN
An encrypted tunnel pushes this whole set of problems up one level: DNS requests and SNI still exist, but they travel inside the tunnel, to the VPN node — the hotel's or café's local network sees only an encrypted stream to one address, not domain names or per-site traffic volume.
Related questions
So does regular HTTPS protect nothing at all?
It protects plenty — the content of a specific page: text, images, form data on submission. It doesn't protect the metadata around the connection: the DNS request, SNI, traffic volume and timing.
Can a network fake a DNS response?
Technically, yes, if DNS requests go out unencrypted and the network is set up to intercept and replace them — that's its own attack category, DNS spoofing. A VPN that routes DNS requests inside the tunnel removes that option from the local network.
Does a VPN hide absolutely everything?
No — the network you're connected to still sees that you're connected to a VPN node. What the node itself sees on its way out to the internet depends on its logging policy, not the encryption protocol.