← Latest briefing

Technology

US senator asks NSA for public guidance on secure VPN use

A lawmaker is urging intelligence officials to outline best practices as technical vulnerabilities in commercial VPNs leave user data exposed.

The short version

  • A US senator has requested that the National Security Agency release public guidance on how to safely use virtual private networks against foreign surveillance.
  • Although government agencies have previously advised using VPNs, they have not specified which tools or practices provide adequate security.
  • The request comes amid concerns over inherent VPN vulnerabilities, including unencrypted metadata and potential traffic exposure at decryption endpoints.

Key facts

  • A US senator called on the National Security Agency to issue public recommendations regarding best practices for VPN usage to counter foreign adversary surveillance.[Ars Technica]
  • While US government agencies have previously suggested using VPNs, they have not provided specific guidance on which services offer sufficient protection.[Ars Technica]
  • VPN protections can be compromised when encrypted tunnels terminate at single servers where decrypted data or IP addresses may be accessed by compromised systems or insiders.[Ars Technica]
  • Commercial VPNs generally do not encrypt metadata such as timestamps, which adversaries can exploit to build intelligence profiles.[Ars Technica]

What remains uncertain

  • It remains unknown whether the National Security Agency will agree to publish public VPN evaluations or usage standards in response to the request.[Ars Technica]

Sources