The NSA Has Been Asked Whether Your VPN Actually Works

Last Updated on September 22, 2026

Senate Asks NSA: Do Normal VPNs Actually Protect You?

A  senator in the USA has asked the NSA if standard VPNs can actually stop foreign surveillance from spying on you, they named Tor, Nym and Apple Private Relay as alternatives.

In this video we break down the the letter from Senator Wyden, why single-hop VPNs struggle with traffic analysis, and what multi-hop and mixnets do differently.

If you use a VPN, you’ve almost certainly heard some version of this: it hides your traffic, your ISP can’t see what you’re doing, and that’s that.  On 2 September, Senator Ron Wyden asked the National Security Agency to reconsider how honest that advice really is.

What actually happened

Wyden wrote to NSA Director General Joshua Rudd, requesting that the agency update its public guidance on VPN configuration. The letter came alongside a Congressional Research Service memo that Wyden had requested, and it’s the memo that carries the weight.  In fact, the memo has almost certainly inspired the letter anyway.

Its central point is actually quite blunt, suggesting that current advice is outdated and inaccurate . The suggestion is that encryption strength alone does not protect you from a well-resourced adversary conducting bulk traffic collection.  Now there’s a lot of evidence that suggests this is very much the case, evidence originating from all over the world.

That sounds counterintuitive, so it’s worth unpacking briefly. When you connect to a VPN, your data gets encrypted. An eavesdropper can’t read the contents.  That’s pretty much agreed, but encryption doesn’t hide everything around the content — especially the metadata. That includes infromation on where traffic comes from, where it’s going, when it was sent, and how much of it there was.  None of this is directly protected by encryption at all.

The single-hop problem

The main concern is specifically about single-hop VPNs. That’s currently the standard commercial setup: your traffic goes into one provider’s server, and out the other side to the web site or application you’re visiting.

If someone can observe both sides of that server, and see the traffic they can look for patterns. Traffic of a certain size goes in at a certain moment; traffic of a similar size comes out a moment later. Match enough of those up and you can start pairing users with the sites they’re visiting — without ever breaking the encryption.

In other words, although the padlock protecting your data stays intact. The pattern around it gives you away.

What might work better

The memo actually points to several tools that spread a user’s information across multiple servers, often based in completely different jurisdictions. That list includes Tor, Nym, and Apple’s iCloud Private Relay.

The logic is fairly straightforward: the more places your traffic has to pass through, and the less any single operator can see, the harder any correlation becomes.

None of these are totally magic. Private Relay doesn’t cover all of your device’s traffic, and none of them promise full anonymity. But the memo suggests that they are significantly harder to analyse than a single provider’s server.

What the NSA and others have said

Wyden also released a July letter from the Office of the Director of National Intelligence, which recommends VPNs as part of basic cyber hygiene — while stressing that provider data-retention and encryption practices matter enormously.  That’s probably the tension at the heart of this. The ODNI still backs traditional VPNs, which many of us use daily and consider outrselves protected. The CRS memo says that their protection has real limits against sophisticated adversaries.  Of course, the bar of a sophisticated adversaries has fallen massively in the last year or so – an attacker with AI on their side effectively has huge technical resources not previously available.  It won’t need a national security organisation to perform these attacks.

And it’s worth being clear about what this letter is. Wyden is at the moment simply asking the NSA a question — whether standard VPNs adequately protect sensitive communications, and whether guidance should point users toward multi-hop alternatives. He is not announcing an answer, although there seems to be some sort of assumption behind it.  The NSA has been asked to respond in unclassified form by 14 October. That response, not the letter, is the thing to watch.

It should also be noted that this is Wyden’s third letter on VPN security since March.

Why it matters if you’re not a spy

The people Wyden names are government personnel, defence contractors, journalists, and human rights defenders — anyone facing an advanced, persistent threat.  The list here is growing daily though you could certainly argue anyone in Russia who wants to access Western sites could potentially be at risk.  For a typical user on public Wi-Fi, a reputable VPN is still doing useful work. It hides your IP, it stops your ISP watching you directly, and it’s far better than nothing.

But “better than nothing” and “protects you from a state-level adversary” are vastly different claims. Wyden’s argument is that the public advice has been blurring them together and AI means that a higher level of security is becoming almost essential for everyday privacy.


Sources