[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fJ7cC_MQ9Kyr-znIloM1oYMbZICZtOf8pGzfyZ6nwH0Y":3},{"article":4,"iocs":49},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":31,"category":32,"article_tags":36},"65c2eaef-cb26-40e3-b68d-721f01c52f96","Wyden seeks upgraded NSA security guidance on commercial VPN use","wyden-seeks-upgraded-nsa-security-guidance-on-commercial-vpn-use-aea0ac","it’s the latest in a sequence of letters to feds from Sen. Ron Wyden, D-Ore., on commercial VPNs. The post Wyden seeks upgraded NSA security guidance on commercial VPN use appeared first on CyberScoop.","Senator Ron Wyden is urging the NSA to update its public guidance on the security risks of commercial VPNs, particularly single-hop configurations. He argues that these standard VPNs do not adequately protect users from sophisticated adversaries and that more secure alternatives like multi-hop and mixnet architectures are available. Wyden also seeks answers regarding foreign surveillance threats against common VPNs, emphasizing the need for clear advice for individuals facing advanced foreign threats.","Senator Ron Wyden asks NSA to update guidance on commercial VPN security risks.","Sen. Ron Wyden, D-Ore., is asking the National Security Agency to update public guidance on the security risks associated with commercial virtual private networks, and to answer questions about foreign surveillance threats against standard VPNs. In a letter to NSA Director Gen. Joshua Rudd that Wyden sent Wednesday, the senator continued his push to warn about standard, commercial VPNs, following letters to federal agency leaders in March and July. “While commercial Virtual Private Networks (VPNs) are recommended by federal agencies and widely marketed as shields against online spying, standard consumer VPNs do not sufficiently protect users from sophisticated adversaries,” Wyden wrote in the letter, first reported by CyberScoop. “Other, more secure alternatives are widely available.” Wyden took aim at “single-hop” VPNs that routes data through one server before arriving at the destination. He cited a Congressional Research Service paper from last month that said “a single-hop VPN, however strongly encrypted, offers essentially no protection against an adversary who can compel… or infiltrate that one provider,” compared to “multi-hop and mixnet architectures [that] directly target and mitigate this weakness” since a second server only knows the IP address of the first server. He also cited a letter responding to an earlier missive that Wyden signed with other lawmakers in an exchange with the Office of the Director of National Intelligence. The office offered a note of caution about scrutinizing VPN providers’ privacy and security policies, but Wyden said “it overlooked the importance of the VPN service’s architecture against sophisticated foreign threats.” Wyden referenced an advisory from the NSA and allied foreign governments last September about a China-sponsored campaign to target telecommunications, government and military networks. He said that the NSA should update its public guidance on VPN configuration. “Americans facing advanced foreign threats — including government personnel, defense contractors, journalists, and human rights defenders — deserve clear, honest advice about how best to protect their communications from surveillance by foreign adversaries. He also asked Rudd to answer a series of questions in an unclassified reply. Some view single-hop commercial VPNs as sufficient for average internet users, and Wyden asked whether they were strong enough to protect “Americans’ sensitive digital footprints against foreign adversaries capable of monitoring internet backbones.” And Wyden wants Rudd to weigh in on the importance and effectiveness of multi-hop anti-surveillance systems, like Apple Private Relay, Tor and Nym, as well as how multi-hop proxy systems fare against mixnet architectures. You can read the full letter below. wyden-letter-vpnDownload Share Facebook LinkedIn Twitter Copy Link","https:\u002F\u002Fcyberscoop.com\u002Fwyden-nsa-commercial-vpn-security-guidance\u002F","https:\u002F\u002Fcyberscoop.com\u002Fwp-content\u002Fuploads\u002Fsites\u002F3\u002F2026\u002F09\u002FGettyImages-2213782698.jpg","2026-09-02T15:00:00+00:00","2026-09-02T16:00:07.560902+00:00",7,[18,21,24,27,29],{"name":19,"type":20},"NSA","vendor",{"name":22,"type":23},"China","threat_actor",{"name":25,"type":26},"Apple Private Relay","product",{"name":28,"type":26},"Tor",{"name":30,"type":26},"Nym","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":31,"icon":33,"name":34,"slug":35},null,"Policy","policy",[37,42,44],{"category":38},{"id":39,"icon":33,"name":40,"slug":41},"614132b8-5837-4952-b8b5-c6c9a32a1d85","Privacy","privacy",{"category":43},{"id":31,"icon":33,"name":34,"slug":35},{"category":45},{"id":46,"icon":33,"name":47,"slug":48},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]