Senator Wyden Urges NSA to Issue Detailed VPN Security Guidance
A Democratic senator is requesting the National Security Agency provide specific recommendations on VPN configurations to help Americans protect communications from foreign surveillance.

What happened
Senator Ron Wyden of Oregon sent a letter Wednesday to NSA Director Joshua M. Rudd requesting updated public guidance on VPN use, specifically addressing technical configurations and security best practices. Wyden's letter asks the NSA to evaluate single-hop versus multi-hop VPN architectures, the effectiveness of random delays and cryptographic padding against timing attacks, and the adequacy of specific services including Apple Private Relay, Nym, and Tor. The senator emphasized that government personnel, defense contractors, journalists, and human rights defenders need clear advice to protect communications from foreign adversaries.
Context
VPNs encrypt internet traffic and mask IP addresses, but significant security gaps exist in current implementations. Encrypted tunnels often terminate at a server that decrypts traffic before forwarding it, exposing decrypted data and routing information to potential compromised servers or insider threats. VPNs also fail to encrypt metadata such as timestamps, which nation-states can use for intelligence profiling. While U.S. agencies have previously recommended VPN use generally, none have provided specific guidance on which services or configurations adequately protect against these vulnerabilities. Wyden's request addresses this gap by seeking NSA expertise on technical architecture choices that meaningfully improve security for high-risk individuals.