US senator calls on the NSA to give guidance for use of VPNs
Ars Technica

US senator calls on the NSA to give guidance for use of VPNs

VPN Options and the Need for Guidance

Open source, commercial, single-hop, multi-hop, mixnet? The array of options is dizzying.

A prominent US senator is asking the National Security Agency to provide guidance to the general public on best practices for using virtual private networks to secure their communications from spying by foreign adversaries. VPNs funnel all of a user's Internet traffic through an encrypted connection to a remote server. The design provides strong assurances that no one between the user and the server can read the encrypted contents. VPNs also allow users to hide their IP addresses from the destination servers they communicate with.

Limitations of VPNs

While US agencies have previously recommended use of VPNs, none have given recommendations on which ones provide adequate protection. There are a host of limitations that can undo many of the protections users may think their VPN provides them:

  • The encrypted tunnel often terminates once a single server decrypts the traffic and sends it on to its final destination. That means the decrypted traffic or the sending and destination IP addresses may be available for snooping by rogue employees or attackers who hack the server.
  • VPNs also don't encrypt certain types of metadata, such as time stamps, allowing nation-states to build profiles that can be useful in intelligence gathering.

With so many nuances, the existing recommendations to use a VPN don't provide enough information for people to make informed decisions.

Sen. Wyden's Letter to the NSA

Sen. Ron Wyden (D-Ore.) is asking the NSA to provide specific recommendations.

"Americans facing advanced foreign threats-including government personnel, defense contractors, journalists, and human rights defenders-deserve clear, honest advice about how best to protect their communications from surveillance by foreign adversaries," Wyden wrote in a letter sent Wednesday to Gen. Joshua Rudd, the director of the NSA. "To that end, I request that you update NSA's existing public guidance on VPN configurations to address this issue."

Specific Technical Questions

The letter touches on some fairly technical details, including the general architecture of a VPN service:

  • Single-hop VPNs - Are they adequate? As noted earlier, these use a single server to decrypt traffic sent by the user and send it to its destination.
  • Multi-hop architectures - In these, traffic is funneled through two or more servers, allowing the first to see only the IP address of the sender and the terminating server to see only the destination address.
  • Random delays and cryptographic padding - These can thwart attacks that detect timing patterns or the size of messages.

Wyden further asks about the adequacy of specific services such as Apple Private Relay, Nym, and Tor.

Read on Ars Technica ↗ ← Back to News

Comments

No comments yet. Start the discussion.