Senator Wyden Urges NSA to Update Guidance on Commercial VPN Security
Senator Ron Wyden is calling on the NSA to provide clearer public guidance on the security limitations of commercial VPNs, particularly against sophisticated foreign adversaries.

Senator Ron Wyden, D-Ore., has formally requested that the National Security Agency (NSA) update its public guidance regarding the security efficacy of commercial virtual private networks (VPNs). In a letter addressed to NSA Director Gen. Joshua Rudd, Wyden expressed concern that standard, single-hop VPNs, widely marketed as protective measures against online surveillance, offer insufficient defense against advanced threats.
Wyden highlighted that these common VPN configurations route user data through a single server, leaving them vulnerable if that server is compromised or compelled by adversaries. He cited a recent Congressional Research Service paper which stated that even strongly encrypted single-hop VPNs provide minimal protection against an adversary capable of infiltrating the VPN provider itself. The senator contrasted this with multi-hop and mixnet architectures, which are designed to mitigate such weaknesses by routing traffic through multiple servers, with each server only knowing the IP address of the preceding one.
This initiative follows previous communications from Wyden to federal agency leaders, where he has consistently raised awareness about the potential security gaps in commercial VPNs. While acknowledging that some agencies recommend VPNs and that providers market them as shields against spying, Wyden argued that these assurances often overlook the architectural vulnerabilities that sophisticated foreign intelligence agencies can exploit. He pointed to an exchange with the Office of the Director of National Intelligence (ODNI) where, in his view, the importance of VPN architecture against advanced foreign threats was downplayed.
Wyden referenced a September advisory from the NSA and allied governments concerning a China-sponsored campaign targeting telecommunications, government, and military networks. He believes this underscores the need for the NSA to provide updated, practical guidance on VPN configurations suitable for protecting Americans facing advanced foreign threats. This includes government personnel, defense contractors, journalists, and human rights defenders who require robust communication security.
The senator posed several specific questions to General Rudd, seeking unclassified responses on critical security matters. He questioned whether single-hop commercial VPNs are adequate for safeguarding sensitive digital footprints of Americans against adversaries capable of monitoring internet backbones. This probes the effectiveness of standard VPNs in the face of state-level surveillance capabilities.
Furthermore, Wyden sought the NSA's assessment on the importance and effectiveness of multi-hop anti-surveillance systems. He specifically asked for an evaluation of solutions like Apple Private Relay, Tor, and Nym, as well as a comparison of how multi-hop proxy systems perform against more advanced mixnet architectures. This indicates a desire for the NSA to endorse or clarify the benefits of more complex privacy-enhancing technologies.
The call for updated guidance reflects a growing concern among policymakers about the adequacy of consumer-grade security tools against increasingly sophisticated nation-state threats. As foreign adversaries develop advanced surveillance and cyberattack capabilities, there is a recognized need for clearer, more technically sound advice for individuals and organizations operating in high-risk environments.
Wyden's efforts aim to ensure that Americans, particularly those in sensitive roles, have access to accurate information to make informed decisions about their online security and privacy, moving beyond generic recommendations to specific, architecturally sound solutions.