Thursday, 3 September 2026
Rīga TV

World and Latvian news in one place

TechnologyPublished: 3 September 2026 at 23:30

US senator urges NSA to issue clear guidance on VPN use

Senator Ron Wyden has asked the NSA to provide specific recommendations on VPN security, arguing existing public guidance lacks enough detail for informed decisions. The letter was sent to the NSA director on Wednesday.

Foto: Ars Technica

US Senator Ron Wyden, a Democrat from Oregon, has asked the National Security Agency to develop detailed public guidance on how to securely use virtual private networks (VPNs) to protect communications from surveillance by foreign adversaries.

VPNs route a user's entire internet traffic through an encrypted connection to a remote server, hiding the user's IP address and shielding content from interception along the way. However, the protection has important limitations. The encrypted tunnel typically ends at a server that decrypts the traffic before forwarding it to its final destination, meaning decrypted data or sender and destination IP addresses could be exposed to rogue employees or attackers who compromise that server. VPNs also fail to encrypt certain metadata, such as timestamps, which can allow nation-states to build profiles useful for intelligence gathering.

Why clearer guidance is needed

While US agencies have previously recommended VPN use in general, none has offered specific guidance on which services provide adequate protection. In a letter sent Wednesday to NSA Director General Joshua M. Rudd, Wyden wrote that Americans facing advanced foreign threats — including government personnel, defense contractors, journalists, and human rights defenders — deserve clear, honest advice on protecting their communications from surveillance.

Wyden is requesting that the NSA update its existing public guidance on VPN configurations to address a range of technical issues. These include the adequacy of single-hop VPN architectures, where one server decrypts and forwards traffic, versus multi-hop setups, where traffic passes through two or more servers so no single server can see both the sender's and destination's IP addresses. He also asked about the use of random delays and cryptographic padding to defend against timing- and message-size-based attacks, as well as the adequacy of specific services, including Apple Private Relay, Nym, and Tor.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category