Network Security

Senator Wyden urges NSA to update VPN guidance amid foreign surveillance concerns

VPN Virtual Private Network Technology Secure Connection Cyber Security Background

Senator Ron Wyden is urging the National Security Agency to revise its cybersecurity guidance to inform Americans that standard virtual private network (VPN) services may not adequately protect them from sophisticated foreign surveillance threats, with further coverage provided by Nextgov.

A Congressional Research Service analysis, requested by Wyden, indicates that foreign intelligence services may be able to link VPN users to specific websites by analyzing the timing and volume of encrypted data traffic. This traffic analysis method, which does not require breaking encryption, could expose a user's online activities. The concern primarily focuses on single-hop VPNs where traffic passes through one server, potentially allowing adversaries monitoring that server to correlate incoming and outgoing data. Wyden argues this risk should be clearly communicated to government personnel, contractors, and journalists who may be targets of espionage.

Current NSA and CISA guidance largely addresses preventing network intrusions that exploit VPN vulnerabilities, recommending measures like timely updates and multi-factor authentication. The Office of the Director of National Intelligence has previously stated VPNs are useful for basic cybersecurity, advising users to review provider encryption and data retention policies, but it remains unclear if they assessed the specific traffic analysis risks associated with conventional VPNs.

Source: Nextgov

An In-Depth Guide to Network Security

Get essential knowledge and practical strategies to fortify your network security.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds