Technology
US senator asks NSA for public guidance on secure VPN use
A lawmaker is urging intelligence officials to outline best practices as technical vulnerabilities in commercial VPNs leave user data exposed.
The short version
- A US senator has requested that the National Security Agency release public guidance on how to safely use virtual private networks against foreign surveillance.
- Although government agencies have previously advised using VPNs, they have not specified which tools or practices provide adequate security.
- The request comes amid concerns over inherent VPN vulnerabilities, including unencrypted metadata and potential traffic exposure at decryption endpoints.
Key facts
- A US senator called on the National Security Agency to issue public recommendations regarding best practices for VPN usage to counter foreign adversary surveillance.[Ars Technica]
- While US government agencies have previously suggested using VPNs, they have not provided specific guidance on which services offer sufficient protection.[Ars Technica]
- VPN protections can be compromised when encrypted tunnels terminate at single servers where decrypted data or IP addresses may be accessed by compromised systems or insiders.[Ars Technica]
- Commercial VPNs generally do not encrypt metadata such as timestamps, which adversaries can exploit to build intelligence profiles.[Ars Technica]
What remains uncertain
- It remains unknown whether the National Security Agency will agree to publish public VPN evaluations or usage standards in response to the request.[Ars Technica]