“While commercial Virtual Private Networks (VPNs) are recommended by federal agencies and widely marketed as shields against online spying, standard consumer VPNs do not sufficiently protect users from sophisticated adversaries,” Sen. Ron Wyden wrote in a letter to the National Security Agency director.
What Wyden asked of NSA Director Gen. Joshua Rudd
In a letter sent Wednesday, Sen. Ron Wyden, D‑Ore., asked the National Security Agency to update its public guidance on the security risks associated with commercial VPNs and to answer a series of questions in an unclassified reply. Wyden framed the request as a continuation of his outreach after letters to federal agency leaders in March and July, and he said Americans facing advanced foreign threats deserve clearer advice about how best to protect their communications from surveillance by foreign adversaries.
The Congressional Research Service finding about single‑hop VPNs
Wyden cited a recent Congressional Research Service paper that contrasted single‑hop VPNs with multi‑hop and mixnet architectures. The CRS language he quoted said that “a single‑hop VPN, however strongly encrypted, offers essentially no protection against an adversary who can compel… or infiltrate that one provider,” and that “multi‑hop and mixnet architectures [that] directly target and mitigate this weakness” do so because a second server only knows the IP address of the first server.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildHow Wyden framed single‑hop versus multi‑hop systems
Wyden took aim specifically at so‑called “single‑hop” commercial VPNs that route data through one server before it reaches its destination. He contrasted those services with multi‑hop anti‑surveillance systems and mixnet architectures, and asked the NSA to weigh in on the importance and effectiveness of named multi‑hop systems — citing Apple Private Relay, Tor and Nym — and to explain how multi‑hop proxy systems compare with mixnet designs when facing sophisticated foreign threats.
Reference to the September advisory on a China‑sponsored campaign
The senator’s letter also referenced an advisory published last September by the NSA and allied foreign governments concerning a China‑sponsored campaign targeting telecommunications, government and military networks. Wyden used that advisory as part of his rationale for seeking updated NSA guidance on VPN configuration and the threat landscape facing high‑risk users.
What this means for government personnel, defense contractors, journalists, and human rights defenders
- Government personnel: Wyden asked the NSA to give clearer, public guidance on VPN configuration, signaling that government staff who face advanced foreign threats should expect more specific recommendations about architectural choices beyond commercial single‑hop services.
- Defense contractors: Citing the CRS finding on single‑hop vulnerabilities, the letter presses the NSA to clarify whether standard commercial VPNs are sufficient to protect sensitive digital footprints from adversaries capable of monitoring internet backbones.
- Journalists and human rights defenders: Wyden explicitly named these groups among Americans who “deserve clear, honest advice” about protecting communications from foreign surveillance, and requested an unclassified response so the guidance can be broadly accessible.
Wyden also noted an exchange with the Office of the Director of National Intelligence in which the ODNI warned against relying solely on providers’ published privacy and security policies. Wyden said that reply “overlooked the importance of the VPN service’s architecture against sophisticated foreign threats,” and he used that point to press the NSA for a technical, publicly available assessment.
The full letter is linked in the CyberScoop post that reported the exchange; Wyden included a downloadable copy labeled “wyden‑letter‑vpn.” He asked the NSA director to respond in an unclassified form so the agency’s views on single‑hop, multi‑hop and mixnet protections would be available to the public and to those the senator named as at higher risk.
Whether the NSA updates its public guidance and how it characterizes the protection single‑hop commercial VPNs can provide against adversaries with backbone‑level visibility are the immediate questions Wyden has put before Director Rudd. The agency’s unclassified reply — and any resulting revisions to configuration guidance — will determine whether federal and high‑risk nonfederal users hear a clearer admonition to favor multi‑hop or mixnet architectures over standard consumer VPNs.




