I know VPNs aren’t the best for privacy, but I’m curious, would a VPN be able to only see a domain and subdomain if the website is https? or can they see more somehow?

  • slem@lemm.ee
    link
    fedilink
    English
    arrow-up
    3
    ·
    edit-2
    9 months ago

    The domain name is sent in cleartext at the start of the connection so that the server knows which virtual server you are connecting to, and which encryption key should be used for the connection (as a single server may be serving multiple sites, which can use separate encryption keys). See e.g. https://en.m.wikipedia.org/wiki/Server_Name_Indication for a more detailed explanation.

    So the VPN provider can see the site you are connecting to, but not the full URL, just like an ISP can.