There are too many ways things can go wrong even with HTTPS. First, how do you get to PayPal? Do you enter www.paypal.com or https://www.paypal.com? If you do the former you can be sslstrip'd [1]. You can check for the padlock icon (plus the correct domain name in the URL) but what if you forget? All it takes to be pwn'd is forgetting once, and if you're hurrying to get a bid in on eBay you'll probably forget. What if you do go to the HTTPS URL but get a certificate warning? I'm sure most HN users would do the right thing and reject it, but for ordinary users it's probably easier to just have a corporate policy that says "always use the VPN when on the road." And even if you always go to the HTTPS URL and reject invalid certificates, what if the site operator does something stupid like include non-HTTPS content or use session cookies without the secure flag?
HSTS is making things much better, but it's not a panacea - you have to have visited the site recently from a trustworthy connection for it to work. I still say VPN is better.