A prominent US senator is pressing the National Security Agency to publish clear public guidance on how Americans should use virtual private networks to shield their communications from foreign surveillance. While federal agencies have previously encouraged VPN use, none have specified which services offer adequate protection.
Senator Ron Wyden, a Democrat representing Oregon, sent the request Wednesday to General Joshua M. Rudd, the director of the NSA. In his letter, Wyden argued that at-risk Americans “deserve clear, honest advice about how best to protect their communications from surveillance by foreign adversaries.” He specifically cited government personnel, defense contractors, journalists, and human rights defenders as groups facing advanced foreign threats.
How VPNs Work and Where They Fall Short
A VPN routes all of a user’s internet traffic through an encrypted connection to a remote server. That design ensures no one positioned between the user and the server can read the encrypted contents, and it also masks the user’s IP address from the destination servers they contact.
However, several limitations can undermine the protection users assume they have. The encrypted tunnel typically ends once a single server decrypts the traffic and forwards it to its final destination. As a result, the decrypted data or the sending and destination IP addresses could be exposed to rogue employees or attackers who compromise the server. VPNs also fail to encrypt certain metadata, such as time stamps, which nation-states can use to build intelligence profiles.
Because of these nuances, Wyden contends that existing recommendations to simply use a VPN do not give people enough information to make informed choices.
The Technical Questions Posed to the NSA
Wyden’s letter asks the NSA to update its public guidance and addresses several detailed points about VPN architecture. One focus is the adequacy of single-hop VPNs, which rely on one server to decrypt user traffic and send it onward. The letter contrasts these with multi-hop architectures, where traffic passes through two or more servers so the first sees only the sender’s IP address and the final server sees only the destination.
The senator also inquires about defensive measures such as random delays and cryptographic padding, which are intended to thwart attacks that analyze timing patterns or message sizes. In addition, he asks the NSA to assess specific services, including Apple Private Relay, Nym, and Tor.
The letter poses three central questions. First, whether standard, single-hop commercial VPNs are sufficient to protect Americans’ sensitive digital footprints from foreign adversaries monitoring internet backbones. Second, whether the NSA recommends multi-hop tools such as Apple Private Relay, Tor, or Nym over standard VPNs for Americans facing heightened surveillance. Third, what technical features, including random delays, padding, and cover traffic, are needed to defend against sophisticated surveillance, and how the NSA evaluates multi-hop systems like Apple Private Relay.
Wyden addressed the request directly to General Joshua M. Rudd, asking the agency to update its existing public guidance on VPN configurations to reflect these concerns.
Source
Image: arstechnica.com