US senator calls on the NSA to give guidance for use of VPNs

← Back to the feed

US senator calls on the NSA to give guidance for use of VPNs

Ars Technica · 2 hours ago

US Senator Ron Wyden has formally asked the National Security Agency to publish clearer public guidance on which types of virtual private networks (VPNs) actually protect Americans from surveillance by foreign adversaries. Although US agencies have long recommended VPN use, none has specified which architectures or providers offer genuinely adequate protection, leaving users with a confusing array of options—commercial, open source, single-hop, multi-hop and mixnet—and no clear basis for choosing between them. This matters because standard VPNs have significant limitations: the encrypted tunnel typically ends at a single server, exposing decrypted traffic or IP addresses to rogue staff or hackers, and metadata such as timestamps often remains unencrypted, letting nation-states build surveillance profiles.

In a letter sent Wednesday to NSA director General Joshua M. Rudd, Wyden said government personnel, defence contractors, journalists and human rights defenders deserve "clear, honest advice" and asked the agency to update its existing public guidance. His questions probe technical specifics, including whether single-hop commercial VPNs are sufficient, whether multi-hop tools such as Apple Private Relay, Tor and Nym should be recommended instead, and what protections like random delays and cryptographic padding are needed against sophisticated traffic analysis. Nym is an open-source, Rust-based client that can route traffic through a decentralised mixnet, Apple Private Relay splits browsing across two servers, and Tor routes traffic through three relays before decryption.

  • Wyden asks NSA to issue clearer public guidance on secure VPN use
  • Standard single-hop VPNs can leak traffic and metadata to attackers
  • Letter asks NSA to assess multi-hop tools like Tor, Nym, Apple Private Relay

New here? Start with this

Standard VPNs work by routing internet traffic through an encrypted tunnel to a single server, which then sends it on to its destination. This hides browsing activity from local networks and internet providers, but the VPN provider itself can usually still see users' real identities and unencrypted traffic details, such as timing data, which is enough for a determined government to piece together who is doing what online.

Ron Wyden is a US senator known for pressing intelligence and technology agencies on privacy and surveillance issues. He has written to the National Security Agency (NSA), the US body responsible for signals intelligence and cybersecurity advice, asking it to say clearly which kinds of VPN actually shield people from spying by hostile foreign states, rather than just recommending VPN use in general terms as it has done before.

The distinction matters because not all VPNs offer the same level of protection: some route traffic through just one server, while others, such as Tor, Apple's Private Relay or the newer Nym network, split or bounce traffic across multiple servers to make tracking harder. People whose safety can depend on strong anonymity, including journalists, activists and government or defence workers, currently have little official guidance to help them tell which options are genuinely secure.

Both sides, in good faith

The strongest fair case each way — we don't pick a winner.

The case for

Advocates for detailed public guidance argue that journalists, human rights defenders, government staff and ordinary citizens are currently forced to make life-affecting security choices with no reliable information, while the technical weaknesses of single-hop VPNs are already understood by sophisticated state adversaries. They contend that withholding clear advice does not protect anyone from hostile intelligence services, who already probe these systems, but merely leaves law-abiding users exposed and confused. On this view, the NSA has both the expertise and a duty to translate that knowledge into plain, actionable recommendations, particularly for those whose safety depends on it.

The case against

Those wary of the request argue that publicly specifying which VPN architectures the NSA considers adequate risks revealing precisely what the agency can and cannot defeat, effectively handing adversaries a map of surveillance blind spots. They also point out that formally endorsing particular tools or providers could create false confidence, since threat capabilities evolve quickly and any officially blessed option could become a priority target or fall out of date. On this view, the agency's caution reflects a genuine tension between operational security and public transparency, not indifference to user safety.

Americas Geopolitics Politics World

Read the full article at the source →