Senator Ron Wyden sent a letter to NSA Director Gen. Joshua Rudd on September 2 asking the agency to update its federal cybersecurity guidance on commercial VPNs, citing a Congressional Research Service memo that found standard, single-hop consumer VPNs do not sufficiently protect users from monitoring by well-resourced foreign intelligence services. The memo’s core finding is that encryption alone is not the relevant protection: even fully encrypted VPN traffic exposes metadata, source, destination, timing, and volume, that a sophisticated adversary watching traffic at internet scale can use to correlate and identify a user without ever breaking the encryption itself.
This is Wyden’s third letter on VPN security since March, and it asks the NSA to answer, in unclassified form by September 20, whether standard VPNs adequately protect sensitive communications and whether the agency should instead point users toward multi-hop tools such as Tor, Nym, or Apple’s iCloud Private Relay, which route traffic through multiple independent jurisdictions rather than a single provider’s server.
“Americans facing advanced foreign threats deserve clear, honest advice about protecting communications from surveillance by foreign adversaries,” Wyden said. For security leaders whose organizations rely on standard commercial VPNs as their answer to “secure remote access,” the original insight worth taking from this letter is not about individual privacy, it is that traffic-analysis surveillance targets the same single-hop architecture that most enterprise VPN deployments also use. A guidance update aimed at protecting individual Americans from foreign intelligence collection would apply just as directly to any organization whose threat model includes a nation-state adversary.
Related on CyberTech: the Treasury Department’s first sanctions action against a VPN provider tied to ransomware enablement, and continuing coverage of state-linked spyware surveillance campaigns.
Source: Office of Senator Ron Wyden