It’s less elitist and more it’s a simple measure that the masses can understand and very simple and easy to implement. Security is hard and security/ encryption done right is even harder.
I have piholes with dnssec running at least upstream for privacy. And a vps I use as both a socks proxy and vpn here and there. But I have the technical know how to implement that.
Let’s say, my parents just wanted a way to make sure their traffic was encrypted from either their ISP or Corp provided iPhone. I wouldn’t tell them to go build a Linode or use Pi-hole. They don’t care. But a vpn with a decent trust rating with nothing more than a login would do it and is easily achievable.
Would I still advise them to be congnizant that other lower level spyware may be on their Corp phone, sure, absolutely. But that’s not always the case. My org doesn’t do that. We give you a phone and pay for service. You can use your iCloud and we have the ability to lock it/decom it because we own it. And can lock them out of email but we can’t run find my iPhone on it.
There have been requests to our provider for more traffic data for x user. So even I run a vpn when using their data.
Another example. I had a buddy going to China for a couple months bye wanted advice on how to secure his stuff. I advised him to use burner devices and chnage passwords yadda yadda. But then the question of accessing email, such as gmail came up. The great firewall is pretty nuts. I set him up an account on my vps and enabled obfs etc on the vpn.
But he also used nord as a backup because he had ton of options there geographically dispersed. In the end, all he needed was nord at all. And when the firewall dropped his states to one node he would just reconnect. It worked just fine.