Tech

US Senator Ron Wyden asks NSA to clarify VPN best practices for foreign surveillance

The letter requests specific technical guidance on single-hop versus multi-hop architectures, with a response deadline of 14 October 2026.

Editorial persona
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: Ars Technica · View original source
US senator calls on the NSA to give guidance for use of VPNs
Markets & Finance

US Senator Ron Wyden has formally requested that the National Security Agency (NSA) provide updated public guidance on virtual private network (VPN) configurations. The letter, addressed to NSA Director Gen. Joshua Rudd, seeks to assist Americans in protecting their communications from foreign surveillance. Wyden argues that while US agencies have previously recommended the use of VPNs, they have not specified which services or architectural features offer adequate protection for sensitive digital footprints.

The senator’s inquiry highlights the complexity of current encryption options. Standard single-hop VPNs terminate encryption at a single server, potentially exposing decrypted traffic or IP addresses to snooping by rogue employees or attackers. In contrast, multi-hop architectures route traffic through two or more servers, allowing the first server to see only the sender’s IP address and the terminating server to see only the destination address. Wyden seeks clarification on whether standard commercial VPNs are sufficient for those facing advanced foreign threats, including government personnel, defence contractors, journalists, and human rights defenders.

The letter specifically inquires about the adequacy of three distinct services: Apple Private Relay, Tor, and Nym. Nym is an open-source VPN client written in Rust that uses a decentralised “mixnet” for random time delays and message reordering. Apple Private Relay employs a multi-hop architecture with servers operated by Apple and third-party content providers, though its protection is limited to the Safari browser on Apple devices. Tor encrypts traffic through three servers before decryption, although some volunteer-operated hops may be controlled by nation-state spies.

Wyden also asked for technical guidance on features such as random delays, cryptographic padding, and cover traffic. These mechanisms are designed to thwart attacks that detect timing patterns or the size of messages. The senator noted that existing recommendations lack the detail needed for informed decision-making, leaving many users unable to determine the best option for their specific threat model.

Micah Sherr, a Georgetown University professor specialising in network security, noted that there is “no trustworthy standardisation” for assessing various VPN services. He observed that it is extremely difficult for ordinary users to determine whether they need a VPN, what a VPN actually buys them, and which one to use, particularly given the potential for misleading advertising.

A memo issued by the Congressional Research Service provides an overview of the available options but offers no criteria for determining which are best. Wyden has requested that the NSA provide answers to these specific questions no later than 14 October 2026.

Continue reading

More from Tech

Read next: Essay challenges reported claims of a 10% AI extinction risk
Read next: Google expands Gemini rollout to Android Auto
Read next: OpenAI begins gradual rollout of GPT-6 Astra across ChatGPT, Work and Codex