US senator demands NSA VPN guidance to block spying

Senator Ron Wyden pushes the NSA for clear, actionable VPN guidance to protect against foreign surveillance threats.

By Central
The letter highlights critical VPN limitations including metadata exposure and decryption risks.
Highlights
  • Senator Wyden argues that existing NSA advice to 'use a VPN' is dangerously vague and insufficient.
  • VPNs do not encrypt metadata like timestamps, leaving users vulnerable to traffic analysis by adversaries.
  • The NSA's response could set a benchmark for cybersecurity industry standards and privacy practices.

A prominent US senator has formally requested that the National Security Agency issue detailed, publicly accessible guidance on using virtual private networks to protect communications from foreign surveillance, marking a significant escalation in the push for clear, actionable cybersecurity advice from the intelligence community. In a letter sent Wednesday to NSA Director Gen. Joshua Rudd, Senator Ron Wyden (D-Ore.) argued that existing recommendations to “use a VPN” are dangerously vague, leaving high-risk individuals such as government personnel, defense contractors, journalists, and human rights defenders without the specific technical knowledge needed to thwart sophisticated state-sponsored adversaries.

The Gap Between General Advice and Effective Protection

The NSA and other US agencies have long endorsed VPNs as a baseline tool for securing internet traffic. The technology funnels all of a user’s data through an encrypted tunnel to a remote server, providing strong assurances that no intermediary can read the contents. VPNs also mask the user’s IP address from the destination server, adding a layer of anonymity. Yet this surface-level recommendation, Wyden contends, ignores a host of nuances that can completely undermine the intended protections.

“Americans facing advanced foreign threats—including government personnel, defense contractors, journalists, and human rights defenders—deserve clear, honest advice about how best to protect their communications from surveillance by foreign adversaries,” Wyden wrote. The letter specifically requests that the NSA update its existing public guidance to address architectural choices, configuration pitfalls, and the adequacy of different VPN designs.

The Critical Limitations That Users Rarely Consider

Many users assume a VPN creates an impenetrable shield, but the reality is far more complex. A fundamental limitation arises at the point where the encrypted tunnel terminates. Most commercial VPN services use a single server to decrypt traffic from the user and forward it to its final destination. Once that decryption happens, the now-plaintext data can be intercepted by rogue employees, compromised infrastructure, or attackers who have breached the VPN provider’s server. The destination and source IP addresses also become visible at that stage, potentially allowing surveillance of who is communicating with whom.

Equally concerning is the fact that VPNs do not encrypt certain types of metadata, such as timestamps. Even if the payload is secure, nation-state actors can build detailed behavioral profiles by analyzing the timing, size, and frequency of data flows. This metadata alone can reveal sensitive patterns—when a journalist files a report, when a defense contractor accesses classified systems, or when a human rights defender contacts a source. Without countermeasures such as randomized delays or cryptographic padding, these signals remain vulnerable to traffic analysis.

Wyden’s letter highlights these exact points, emphasizing that general exhortations to “use a VPN” provide no guidance on how to mitigate such risks. The senator is pressing the NSA to produce recommendations that go beyond marketing slogans and into the technical realities of threat models facing American targets.

Single-Hop vs. Multi-Hop Architectures: A Core Question

One of the most technical inquiries in Wyden’s letter relates to the fundamental architecture of a VPN service. A single-hop VPN—the common model where traffic passes through one server—leaves both the original IP address and the final destination visible to that server. This creates a single point of failure and a single point of surveillance. A multi-hop architecture, on the other hand, routes traffic through two or more servers. The first server sees only the user’s IP address, while the final server sees only the destination address. No single node sees both, making it far harder for an adversary to correlate sender and receiver.

Wyden explicitly asks the NSA to evaluate whether multi-hop VPNs offer sufficient protection for individuals facing advanced foreign threats. He also seeks guidance on whether such architectures introduce new vulnerabilities, such as increased latency or added complexity that might degrade security in practice.

Countermeasures Against Traffic Analysis: Random Delays and Padding

Beyond architecture, the letter delves into techniques that can defeat traffic analysis. Even with encryption, the size of data packets and the timing of their transmission can reveal information. For example, if a user uploads a large file at a consistent time each day, an observer can infer that activity even without decrypting the content. Cryptographic padding—adding random data to make packets a uniform size—and random delays can obscure these patterns. Wyden asks the NSA to assess the effectiveness of such countermeasures and to recommend specific implementations.

These are not theoretical concerns. State-sponsored groups, including those from China, Russia, and Iran, have long employed traffic analysis to identify targets, map communication networks, and uncover sensitive activities. The absence of padding and jitter in many commercial VPN services leaves users exposed to exactly the kind of surveillance the tools are meant to prevent.

Wyden’s Specific Questions: Apple Private Relay, Nym, and Tor

The senator’s letter does not stop at general principles. It asks the NSA to evaluate the adequacy of three specific technologies: Apple Private Relay, Nym, and Tor. Each represents a different approach to anonymizing and securing traffic.

Apple Private Relay, available to iCloud+ subscribers, routes traffic through two separate relays: one that knows the user’s IP address but not the destination, and another that knows the destination but not the user’s IP. This is a form of multi-hop design, but with key limitations—it applies only to Safari traffic and does not cover all internet activity. Wyden wants to know whether this architecture meets the bar for users facing advanced threats.

Nym is a mixnet-based privacy network that uses layered encryption and random delays to obscure metadata. Its design is fundamentally different from traditional VPNs and is aimed specifically at defeating traffic analysis. However, it is less mature and less widely adopted. The letter asks whether Nym offers meaningful protections beyond what a well-configured multi-hop VPN can provide.

Tor, the most well-known anonymity network, routes traffic through three volunteer-run relays and includes built-in padding and timing protections. Yet Tor is also known for its latency and for being a target of surveillance by various governments. Wyden’s inquiry seeks clarity on whether Tor remains a viable option for users who need both security and practical usability, or whether it has been sufficiently compromised by state actors.

By naming these specific services, Wyden signals that the NSA should not simply repeat generic advice but should instead offer concrete evaluations of the tools available to the public. This is a direct challenge to the agency to move from abstract principle to practical recommendation.

Why the NSA’s Existing Guidance Falls Short

The NSA has published guidance on VPN use before, most notably in the “NSA’s Top Ten Mitigation Strategies” and in various cybersecurity information sheets. However, these documents focus on enterprise environments—securing corporate networks, remote access for employees, and protecting classified systems. They offer little to individuals who must protect their own communications without the backing of a dedicated IT department.

Wyden’s letter implicitly criticizes this gap. The threat landscape has expanded to include journalists, activists, and ordinary citizens who may be targeted by foreign intelligence services. The NSA’s silence on which VPNs to use, how to configure them, and what trade-offs to accept leaves these individuals to rely on marketing claims from VPN providers that may not prioritize security over profit.

Furthermore, the NSA’s own role in surveillance—particularly its historical collection of metadata under programs revealed by Edward Snowden—creates a trust deficit. Wyden’s request implicitly asks the agency to separate its intelligence-gathering mission from its cybersecurity advisory role and to provide advice that genuinely serves the public interest.

The Broader Context: State-Sponsored Surveillance and the Need for Transparency

This is not the first time Wyden has pressed the intelligence community on surveillance issues. He has been a consistent advocate for transparency around NSA programs, including bulk metadata collection and warrantless wiretapping. The VPN guidance request fits into a broader pattern of holding the agency accountable while also leveraging its expertise to protect vulnerable populations.

Foreign adversaries are actively exploiting the gaps in VPN knowledge. Reports from the Cybersecurity and Infrastructure Security Agency (CISA) and private threat intelligence firms have documented advanced persistent threat (APT) groups using traffic analysis, DNS poisoning, and compromised VPN infrastructure to target specific individuals. For a journalist covering authoritarian regimes or a defense contractor handling sensitive technologies, a poorly chosen VPN can be worse than no VPN at all—it can create a false sense of security while actually facilitating surveillance.

The letter arrives at a moment when VPN usage is at an all-time high, driven by privacy concerns, remote work, and geopolitical instability. Yet the market is flooded with services that vary wildly in quality. Some log user data, sell browsing histories, or rely on infrastructure in jurisdictions with lax privacy laws. Without authoritative guidance from an entity like the NSA, users have no reliable way to distinguish between a trustworthy service and a honeypot.

What an Updated NSA Guidance Would Look Like

If the NSA responds to Wyden’s request—and the senator’s oversight role gives him significant leverage—the resulting document could become a de facto standard for evaluating VPNs in high-threat scenarios. The letter asks for guidance on at least five specific areas:

  • Whether single-hop or multi-hop architectures are preferred for different threat models.
  • How to implement random delays and cryptographic padding to defeat traffic analysis.
  • The adequacy of Apple Private Relay, Nym, and Tor for users facing advanced foreign threats.
  • What metadata is still exposed even with a properly configured VPN, and how to mitigate that exposure.
  • How to evaluate the trustworthiness of VPN providers, including their logging policies, jurisdiction, and infrastructure security.

Such a document would be invaluable not only for individual users but also for organizations that need to issue clear directives to their employees. It could also pressure VPN providers to improve their security claims and to adopt the best practices recommended by the nation’s top signals intelligence agency.

The Challenge of Balancing Security and Practicality

Any NSA guidance must navigate a delicate balance. The most secure configurations—multi-hop with padding and delays—come with significant performance trade-offs. Tor, for example, can be painfully slow for everyday browsing. Nym’s mixnet adds minutes of latency. A defense contractor might be willing to accept that for sensitive communications, but a journalist on a deadline may not. The guidance should provide a tiered set of recommendations based on risk level, rather than a one-size-fits-all prescription.

Another challenge is the rapid evolution of both threats and defenses. What works today may be broken tomorrow by a new traffic analysis technique or a compromise of a major VPN provider. The NSA would need to commit to regular updates, or at least to a mechanism for flagging changes.

Wyden’s letter does not demand a quick fix; it asks for a foundational framework. The NSA has the technical expertise to produce such a framework. The question is whether it has the institutional will to share that knowledge openly, especially given its own historical involvement in surveillance activities that VPNs are designed to counter.

What the Response Could Mean for the Future of Digital Privacy

If the NSA accedes to Wyden’s request, the impact could extend far beyond the immediate audience of at-risk individuals. Clear, authoritative guidance would set a benchmark for the entire cybersecurity industry. It would likely be cited by courts, adopted by corporate compliance programs, and used by privacy advocates to hold VPN providers accountable. It could also reduce the information asymmetry that currently leaves most users unable to make informed choices.

Conversely, a refusal or a vague response would signal that the NSA is unwilling to empower the public against foreign surveillance—a politically damaging stance for an agency that increasingly positions itself as a defender of American networks. Either way, the letter forces a moment of reckoning. The NSA must decide whether its public role as a cybersecurity advisor can coexist with its intelligence mission, or whether the two are fundamentally in conflict.

For now, the ball is in Gen. Rudd’s court. Wyden has given the agency a detailed, technically sophisticated set of questions, and the expectation is that the answers will be equally substantive. The outcome will shape not only how vulnerable Americans protect themselves from foreign spying, but also the broader debate about the proper relationship between the intelligence community and the people it is meant to serve.

Share This Article