Today's AI/ML headlines are brought to you by ThreatPerspective

Digital Event Horizon

US Senator Requests Guidance from NSA on Best Practices for Using Virtual Private Networks


US Senator Ron Wyden has asked the National Security Agency (NSA) for guidance on the best practices for using virtual private networks (VPNs) to secure their communications from foreign adversaries. The request comes as a result of the existing recommendations to use a VPN, which do not provide enough information for people to make informed decisions.

  • A prominent US senator has asked the NSA for guidance on VPN security to protect communications from foreign adversaries.
  • VPNs provide strong assurances of security but have limitations that can undo many protections.
  • Experts warn that VPNs can be vulnerable to attacks, such as rogue employees or attackers hacking the server, and do not encrypt all metadata.
  • The NSA is asked to provide specific recommendations on which VPN services are best for different threat models.
  • The request comes as a response to the need for clear and honest advice on how to protect communications from surveillance.



  • A prominent US senator has asked the National Security Agency (NSA) for guidance on the best practices for using virtual private networks (VPNs) to secure their communications from foreign adversaries. The request comes at a time when the array of VPN options available to the general public is dizzying, and many users are unsure of which ones provide adequate protection.

    The question of VPN security has become increasingly important in the digital age, where sensitive information and communications are often transmitted over the internet. VPNs, which funnel all of a user's internet traffic through an encrypted connection to a remote server, provide strong assurances that no one between the user and the server can read the encrypted contents. However, like any security measure, VPNs have limitations that can undo many of the protections users may think they provide.

    According to experts, the encrypted tunnel often terminates once a single server decrypts the traffic and sends it on to its final destination. This means that the decrypted traffic or the sending and destination IP addresses may be available for snooping by rogue employees or attackers who hack the server. Furthermore, VPNs do not encrypt certain types of metadata, such as time stamps, allowing nation-states to build profiles that can be useful in intelligence gathering.

    The request from Senator Ron Wyden (D-Ore.) comes as a result of the existing recommendations to use a VPN, which do not provide enough information for people to make informed decisions. Wyden is asking the NSA to provide specific recommendations on which VPN services are best for different threat models, such as single-hop commercial VPNs, multi-hop architectures, and specific services like Apple Private Relay, Tor, and Nym.

    The questions asked by Wyden are fairly technical, including the adequacy of single-hop VPNs, multi-hop architectures, and the use of random delays and cryptographic padding to thwart attacks that detect timing patterns or the size of messages. The letter also inquires about the adequacy of specific services like Nym, which is an open-source VPN client written in Rust, a memory-safe programming language that's resistant to attacks exploiting buffer overflows or other types of memory-corruption bugs. Nym can route traffic through a decentralized "mixnet," which provides random time delays and the reordering of messages.

    Another service mentioned is Apple Private Relay, which provides multi-hop browsing using two servers, one operated by Apple and the other by a third-party content provider. Tor is a privacy service that encrypts traffic and sends it through three servers before decrypting it and sending it to its final destination.

    Each of these services comes with its own pros and cons, and there is no trustworthy standardization for assessing various VPN services. This makes it extremely difficult for ordinary users to determine whether they need a VPN, what a VPN actually buys them, and which one to use.

    Experts like Micah Sherr, a Georgetown University professor specializing in network security, have expressed concerns about the lack of standardization in the VPN market. "There's no trustworthy standardization" for assessing various VPN services, Sherr said in an interview. "The VPN ads you get in YouTube commercials can be incredibly misleading. It's extremely difficult for ordinary users to determine whether they need a VPN, what a VPN actually buys them, and which one to use."

    The request from Senator Wyden comes as a response to the need for clear and honest advice on how to protect communications from surveillance by foreign adversaries. The NSA is required to provide answers no later than October 14.



    Related Information:
  • https://www.digitaleventhorizon.com/articles/US-Senator-Requests-Guidance-from-NSA-on-Best-Practices-for-Using-Virtual-Private-Networks-deh.shtml

  • https://arstechnica.com/security/2026/09/us-senator-calls-on-the-nsa-to-give-guidance-for-use-of-vpns/


  • Published: Thu Sep 3 16:10:05 2026 by llama3.2 3B Q4_K_M











    © Digital Event Horizon . All rights reserved.

    Privacy | Terms of Use | Contact Us