A prominent US senator is asking the National Security Agency to provide guidance to the general public on best practices for using virtual private networks to secure their communications from spying by foreign adversaries.
VPNs funnel all of a user’s Internet traffic through an encrypted connection to a remote server. The design provides strong assurances that no one between the user and the server can read the encrypted contents. VPNs also allow users to hide their IP addresses from the destination servers they communicate with. While US agencies have previously recommended use of VPNs, none have given recommendations on which ones provide adequate protection.
It’s all in the nuances
There are a host of limitations that can undo many of the protections users may think their VPN provides them. For instance, the encrypted tunnel often terminates once a single server decrypts the traffic and sends it on to its final destination. That means the decrypted traffic or the sending and destination IP addresses may be available for snooping by rogue employees or attackers who hack the server. VPNs also don’t encrypt certain types of metadata, such as time stamps, allowing nation-states to build profiles that can be useful in intelligence gathering.
With so many nuances, the existing recommendations to use a VPN don’t provide enough information for people to make informed decisions. Sen. Ron Wyden (D-Ore.) is asking the NSA to provide specific recommendations.
“Americans facing advanced foreign threats—including government personnel, defense contractors, journalists, and human rights defenders—deserve clear, honest advice about how best to protect their communications from surveillance by foreign adversaries,” Wyden wrote in a letter sent Wednesday to Gen. Joshua Rudd, the director of the NSA. “To that end, I request that you update NSA’s existing public guidance on VPN configurations to address this issue.”
Specific questions touch on some fairly technical details, including the general architecture of a VPN service. They include the adequacy of single-hop VPNs, which, as noted earlier, use a single server to decrypt traffic sent by the user and send it to its destination. It also asks about multi-hop architectures, in which the traffic is funneled through two or more servers, allowing the first to see only the IP address of the sender and the terminating server to see only the destination address. The letter also inquires about the use of random delays and cryptographic padding to thwart attacks that detect timing patterns or the size of messages. Wyden further asks about the adequacy of specific services such as Apple Private Relay, Nym, and Tor.



