The hotel might be able to see that you visited a certain website but thats about it.
Which is not that trivial to begin with.
How hard would it be to take over the dns and simulate a fake VPN too?
Or just constantly disconnect the vpn and hope the user stops using it for a while.
And, I guess, just ignore anything thats not https.
Or just be okay if your hotel blocks certain ports or destinations, which I've had happen multiple times.
Don't you have to trust the CAs in any case?
I frequently access my bank info etc. on such trips. With a VPN at least I have fewer random threat vectors to consider on a network.
"bank info" in this case being anything from logging in to check my balance, pay bills or even contact them via their secure messaging because I'm disputing a transaction.
It doesn't eliminate all threats, but I'm not a secret agent ninja that needs 100% hardened communications. I just need a modicum of assurance.