> OK, but what about my DNS and TLS records being exposed to everyone so they can follow what I am doing? In a public place, anyone can look at your display already. Or, if you are worried about your ISP selling your traffic data, there are better options for you. Use DNS over HTTPS, for example. You have to use a VPN provider you trust better than your ISP/Wi-Fi provider. Also, as Encrypted Client Hello is about to start soon, it will be exponentially harder for eavesdroppers to figure out which sites you are trying to visit.
Encrypting DNS is a nice start, but the ISP can still see the IPs you're connecting to, which is enough for a lot of sites, and Encrypted Client Hello is about to start soon is a lot of words to say "today, your ISP can see the domain on every HTTPS connection you make". So no, distrusting my ISP is absolutely a compelling reason to use a VPN. (And lest you say "but do they actually spy on you?", I literally got a letter from AT&T informing me that they were going to start monetizing information mined from my connections.)
> But if you care about privacy, the answer is always ToR, ToR browser or Tails, and never VPN. Except in cases where you first have to hide your ToR usage using a VPN, which is a rare exception among users. If you don’t understand why you would need that, you probably don’t need that complexity. Tor Browser uses uncountable techniques that prevent tracking your browser. And if your privacy is essential against local Wi-Fi attackers, your ISP, why is the ad industry not in scope? Adblockers are only half the solution against tracking.
I mean, yeah I also use uBlock, but TOR makes harsher tradeoffs than are necessarily needed (multiple hops is really safe but also really slow). I'm just hiding from my ISP's prying eyes; I explicitly don't include the NSA in my threat models and lesser methods are Good Enough™ for websites tracking me.