Senator Presses NSA to Update VPN Guidance as Single-Hop Architecture Draws Scrutiny

Ron Wyden has written to the NSA Director asking for clearer public advice on commercial VPN limitations and the stronger alternatives available to high-risk users.

AI-generated illustration depicting policy for the story: Senator Presses NSA to Update VPN Guidance as Single-Hop Architecture Draws Scrutiny

Summary

  • Senator Ron Wyden has formally asked NSA Director Gen. Joshua Rudd to update public guidance on the security risks of commercial, single-hop VPNs.
  • A Congressional Research Service paper cited in the letter states that a single-hop VPN offers ‘essentially no protection’ against an adversary able to compel or infiltrate that one provider.
  • Wyden singles out high-risk groups — government personnel, defence contractors, journalists and human rights defenders — as needing more honest official advice.
  • Multi-hop and mixnet architectures, including Apple Private Relay, Tor and Nym, are raised as alternatives that materially reduce exposure to sophisticated foreign surveillance.
  • Wyden has requested an unclassified reply addressing whether single-hop VPNs are adequate against adversaries capable of monitoring internet backbones.

The Letter and Its Context

US Senator Ron Wyden (D-OR) wrote to National Security Agency Director General Joshua Rudd this week, asking the agency to update its public guidance on commercial VPN security. The letter, first reported by CyberScoop, continues a line of advocacy that Wyden has pursued since at least March, including earlier correspondence with federal agency leaders and a joint letter with other lawmakers to the Office of the Director of National Intelligence.

The Core Concern: Architecture Matters

Wyden’s principal technical argument centres on the single-hop VPN model, in which user traffic is routed through one server before reaching its destination. He cited a recent Congressional Research Service paper concluding that such a setup, regardless of encryption strength, offers ‘essentially no protection against an adversary who can compel or infiltrate that one provider.’ The implication for organisations whose staff or contractors face nation-state surveillance is direct: encrypting traffic means little if a capable adversary can go straight to the intermediary.

The ODNI Response and Its Gap

An earlier reply from the Office of the Director of National Intelligence, responding to a previous letter Wyden co-signed, urged caution in reviewing VPN providers’ privacy and security policies. Wyden acknowledged that advice but said it missed the point. Policy review, in his assessment, does not address the structural vulnerability of a single-hop architecture when faced with a sophisticated foreign threat actor — an adversary who need not break encryption if they can simply access the intermediary.

China-Linked Activity Cited as Backdrop

To frame the threat environment, Wyden referenced a September advisory issued jointly by the NSA and allied foreign governments about a China-sponsored campaign targeting telecommunications, government and military networks. The senator did not draw a direct causal line between that campaign and VPN architecture specifically, but used it to illustrate the calibre of adversary that current public guidance should be measured against.

Alternatives Wyden Wants the NSA to Assess

The letter asks Rudd to address, in an unclassified response, several specific questions. These include whether single-hop commercial VPNs provide adequate protection for Americans’ sensitive digital activity against adversaries with the capability to monitor internet backbone infrastructure. Wyden also wants the NSA’s assessment of multi-hop proxy systems — naming Apple Private Relay, Tor and Nym as examples — and how those compare with mixnet architectures, which introduce additional layers of traffic obfuscation. The senator acknowledged that some regard single-hop VPNs as sufficient for ordinary users, but drew a distinction for those facing advanced foreign threats.

Who Is Identified as Vulnerable

Wyden’s framing is explicit about the target population: government personnel, defence contractors, journalists and human rights defenders. These are not edge cases for enterprise security teams — they describe a significant portion of the workforce in sectors that already sit in the crosshairs of state-sponsored threat actors. The concern is that official and commercially promoted guidance has not kept pace with the threat model those users actually face.

Why it matters

For CISOs, particularly those operating in government, defence, critical infrastructure or sectors adjacent to sensitive foreign policy matters, this letter signals that the adequacy of commercial VPN deployments is coming under formal regulatory and legislative scrutiny. If the NSA updates its public guidance in response — which remains uncertain; Wyden has only made a request — it could shift baseline expectations for acceptable remote access controls, especially for high-risk roles or travel to jurisdictions where internet backbone surveillance is a realistic threat. Even before any official update, security leaders should be reviewing whether their current VPN architecture is appropriate for their actual threat model, not simply for the average consumer use case that many commercial VPN products are designed around.

What to do now

  • Review whether your organisation’s VPN deployment uses a single-hop architecture and assess whether that model is appropriate given the threat environment your personnel operate in.
  • Identify high-risk user groups — including government liaisons, defence contractors, executives travelling to high-risk jurisdictions, and any staff engaged in sensitive communications — and evaluate whether standard commercial VPN tools meet their specific exposure profile.
  • Examine the privacy and security policies of incumbent VPN providers, as recommended by the ODNI, noting that policy review alone does not address architectural limitations.
  • Monitor NSA public guidance for any updates following Senator Wyden’s request, as changes could affect compliance expectations and procurement standards.
  • Where high-risk use cases are identified, investigate multi-hop proxy or mixnet alternatives and assess their operational feasibility for relevant user groups.

Sources