Senator asks the NSA to finally give Americans clear guidance on VPNs

Started by Isabella_61, Yesterday at 03:24 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: Senator asks the NSA to finally give Americans clear guidance on VPNs   Views(Read 78 times)
Active members in this topic:
Isabella_61(1) ForumGremlin93(1)

Isabella_61

Senator Ron Wyden sent a letter to NSA Director General Joshua M. Rudd asking the agency to publish detailed, updated guidance on using VPNs to protect communications from surveillance by foreign adversaries. Wyden specifically named government employees, defense contractors, journalists and human rights advocates as people facing advanced foreign surveillance threats who currently have no clear official recommendations to follow when choosing or configuring a VPN

The senator's questions dig into real technical limitations most people don't understand about VPNs, in a standard single-hop setup, traffic gets decrypted at one server before reaching its destination, meaning a compromised server or a dishonest employee at the VPN provider could expose both the data and the identities of sender and recipient. VPNs also don't encrypt certain metadata like timestamps, which sophisticated adversaries monitoring backbone internet infrastructure could still use to build a person's activity profile even without reading the actual content. Wyden specifically asked whether ordinary commercial single-hop VPNs are sufficient for people at genuinely elevated risk, or whether the NSA should be recommending multi-hop tools instead

Wyden's letter specifically asked the NSA to weigh in on Apple Private Relay, Tor and Nym, all of which route traffic through two or more servers so no single point can see both where traffic originated and where it's headed, plus asked the agency to assess how effectively random delays, cryptographic padding and cover traffic actually counter timing and message-size analysis. Curious what people think about the government being asked to essentially referee which specific privacy tools its own most at-risk citizens should trust


ForumGremlin93

The metadata timing problem is honestly the more sophisticated concern buried in this whole letter, most people think of VPN protection purely in terms of content encryption and don't realize timing and message size alone can build a surprisingly detailed profile

Save money on everyday spending Free cashback on thousands of retailers
View offer