nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqwvdduc0ag4f52utyuj6tycglevzjtzp7xyujycmv843a44rvrq8qxg5cx7 (nprofile…5cx7) Yep - Tailscale is free and you can set it to push everything via a machine at home as well.
Transparent proxies can't work with HTTPS unless you go through the pain of installing a certificate authority in your browser to enable them. You're absolutely safe with coffee shop wifi. There is not a chance that you'll install a CA without knowing what you're doing. And, look up "certificate pinning": if you trick a user into installing a new certificate, it *still* won't work.
You're right, HTTPS never encrypts the domain name: so the websites you visit are still visible - just not what you do on them. So Starbucks, or your hotel, knows which bank you're with, as one example.
"I wasn't talking about Mullvad tracking you" - I was responding to "the VPN provider still very much knows who you are and what you did". In Mullvad's case, all they know is "you" are someone who bought one of the 2,500 sealed vouchers they sent to Amazon. (And your IP address).
