Wyden Calls on NSA to Update Federal Cybersecurity Guidance for VPNs

Following a CRS memo, Wyden presses the NSA for answers on protecting Americans’ communications from foreign surveillance

Washington, D.C. – U.S. Senator Ron Wyden, D-Ore., today urged General Joshua M. Rudd, the Director of the National Security Agency (NSA) to update federal cybersecurity guidance for Virtual Private Networks (VPNs) to address surveillance threats posed by foreign intelligence agencies. 

A Congressional Research Service (CRS) memo, requested by Senator Wyden and released along with the letter, highlights the vulnerability of consumer VPNs to surveillance by intelligence agencies capable of monitoring large swaths of the internet. The CRS memo cautions that “encryption strength alone does not protect users from an advanced, persistent threat conducting bulk data traffic collection.” Even when data traffic is encrypted, it can reveal metadata – such as its source, destination, timing, and volume – that foreign adversaries can analyze and correlate across networks to potentially identify and track users’ internet browsing without breaking the encryption 

The CRS memo notes that other technologies, including Apple iCloud Private Relay, Tor, Nym can better protect users from such surveillance by sending their data through multiple servers, often in different jurisdictions. 

Americans facing advanced foreign threats—including government personnel, defense contractors, journalists, and human rights defenders—deserve clear, honest advice about how best to protect their communications from surveillance by foreign adversaries,” Wyden wrote to General Joshua M. Rudd.

Wyden also released a letter he received in July from the Office of the Director of National Intelligence (ODNI), which recommends VPNs as part of basic cyber hygiene but stressed the importance of VPN providers’ data retention and encryption practices. The DNI guidance did not address the vulnerability of consumer VPNs to foreign surveillance or the relative benefits of multi-server technologies like Apple iCloud Private Relay, Tor and Nym. In addition to requesting that NSA update its existing guidance related to VPNs, Wyden requested that NSA provide unclassified responses to the following questions by September 20, 2026:

  1. Are standard, single-hop commercial VPNs sufficient to protect Americans’ sensitive digital footprints from foreign adversaries monitoring internet backbones?
  2. Does the NSA recommend multi-hop tools such as Apple Private Relay, Tor, or Nym over standard VPNs for Americans facing heightened surveillance threats?
  3. What technical features, such as random delays, padding, and cover traffic, are needed to defend against sophisticated surveillance, and how does the NSA assess multi-hop systems like Apple Private Relay compared with Tor and Nym?

Wyden has been at the forefront of this issue, urging the Trump administration last month to end its use of insecure remote access software.

A copy of the full letter sent to General Rudd, the CRS memo and the letter sent to Senator Wyden from the ODNI is available here

A web version of this release is here.

###