By Open Chronicle Newsdesk with agencies
A senior US senator is urging the National Security Agency to update its cybersecurity guidance on commercial virtual private networks, warning that VPN encryption alone may not protect Americans from sophisticated foreign intelligence services capable of monitoring internet traffic on a large scale.
Sen. Ron Wyden, an Oregon Democrat, called on the NSA to provide clearer guidance after a Congressional Research Service analysis concluded that foreign intelligence agencies could potentially identify the websites visited by VPN users without breaking the encryption protecting their communications.
Instead, an adversary with sufficient visibility into global internet infrastructure could use a technique known as traffic analysis, comparing patterns of encrypted information entering a VPN server with traffic leaving it.
The findings raise important questions about a technology widely promoted as a way to improve online privacy.
Encryption Does Not Solve Every Surveillance Problem
VPN services establish an encrypted connection between a user’s device and a VPN server. They are commonly used to protect communications on public Wi Fi networks, conceal users’ internet protocol addresses and prevent internet service providers from directly observing their browsing activity.
But the CRS analysis requested by Wyden highlights an important limitation.
An intelligence service does not necessarily need to decrypt VPN traffic to determine where it is going.
By monitoring both sides of a VPN connection, an adversary could compare characteristics such as the timing and volume of encrypted traffic entering and leaving a server. Matching those patterns could potentially associate an individual user with particular websites or online services.
“Encryption strength alone does not protect users from an advanced, persistent threat conducting bulk traffic collection,” CRS concluded.
The technique becomes particularly significant when dealing with intelligence agencies capable of observing large sections of global communications infrastructure.
Single Hop VPNs Under Scrutiny
The concern primarily involves conventional single hop VPN services.
With these systems, a user’s internet connection travels through one VPN provider’s server before continuing toward its final destination.
That server effectively becomes an intermediary between the user and the wider internet.
An intelligence organization capable of monitoring communications entering and leaving that infrastructure could potentially correlate the two streams, even if it cannot read the encrypted information itself.
Wyden argues that this limitation needs to be explained more clearly, particularly to people likely to be targeted by sophisticated espionage operations.
That could include government officials, federal contractors, journalists, researchers and others handling sensitive information.
“Americans facing advanced foreign threats … deserve clear, honest advice about how best to protect their communications from surveillance by foreign adversaries,” Wyden wrote to NSA Director Gen. Joshua Rudd.
Wyden has requested unclassified answers from the agency by October 14.
How Global Surveillance Makes Traffic Analysis Possible
The potential vulnerability reflects the extraordinary scale of modern intelligence collection.
Major intelligence powers, including the United States and China, have developed extensive capabilities for monitoring global telecommunications.
Such access can come through domestic legal authorities as well as intelligence operations targeting telecommunications companies, internet infrastructure and undersea fiber optic cables carrying enormous quantities of international data.
An intelligence service with visibility across multiple parts of that infrastructure could potentially observe a user connecting to a VPN while simultaneously monitoring traffic emerging from the VPN provider.
Patterns could then be compared.
The encryption itself would remain intact, but information about who is communicating, when communications occur and how much data is transferred can sometimes reveal valuable intelligence.
Multi Hop Privacy Systems Offer Additional Protection
The Congressional Research Service pointed to architectures including Tor, Nym and Apple’s iCloud Private Relay as examples of systems that can make traffic analysis more difficult.
Rather than placing all trust in a single intermediary, these technologies can distribute information about the user and the destination across multiple servers.
This separation makes it harder for any single observer to associate the origin of internet traffic with its final destination.
However, none provides guaranteed anonymity.
Apple’s Private Relay also does not protect every type of traffic generated by a device, meaning it is not a direct substitute for a full VPN in every situation.
The CRS assessment therefore suggests that users facing sophisticated intelligence threats should consider not simply whether their traffic is encrypted, but how their privacy service is architected.
Existing NSA Guidance Focuses on Hacking
Current guidance from the NSA and the Cybersecurity and Infrastructure Security Agency largely addresses a different VPN threat.
Their recommendations concentrate on securing remote access VPN systems against hackers attempting to exploit vulnerabilities and gain access to government or corporate networks.
Measures include rapidly installing security patches, enabling multifactor authentication and minimizing unnecessary features exposed to the internet.
Those recommendations remain important, but Wyden argues they do not adequately address the separate problem of large scale traffic analysis conducted by foreign intelligence agencies.
His request could therefore lead to a broader definition of what constitutes secure VPN use for people facing advanced surveillance threats.
Intelligence Community Offers More Cautious Assessment
The Office of the Director of National Intelligence provided a separate assessment in July that Wyden also released Wednesday.
ODNI described VPNs as useful basic cybersecurity tools and advised consumers to examine providers’ encryption standards, privacy policies and data retention practices.
The intelligence office also noted another important privacy consideration: VPN providers themselves may know the identities of their customers and could retain information about their activities.
It remains unclear, however, whether ODNI specifically examined the traffic correlation vulnerabilities highlighted by CRS or compared traditional single hop VPN services with privacy systems using multiple intermediaries.
Chinese Telecom Presence Adds Urgency
Wyden’s request comes amid growing concern in Washington about Chinese access to American telecommunications infrastructure.
A bipartisan investigation by the House committee focused on China recently found that three Chinese telecommunications companies had maintained equipment, data center space and network connections inside the United States despite federal efforts to restrict their presence.
Those findings have intensified concerns about whether foreign governments could retain infrastructure capable of supporting surveillance or cyber operations against American targets.
For intelligence agencies, communications security increasingly involves more than simply protecting the contents of messages.
Metadata, routing information, infrastructure access and traffic patterns can all provide valuable information even when strong encryption prevents an adversary from reading the underlying data.
VPNs Remain Useful, But Not Invisible
The congressional analysis does not conclude that VPNs are useless.
For ordinary users, a reputable VPN can still provide significant protection against common threats, particularly on insecure networks, while reducing the amount of browsing information directly visible to internet service providers.
The issue is the level of adversary against which that protection is expected to work.
Commercial VPN marketing can sometimes create the impression that encrypted connections provide complete anonymity. The CRS findings suggest that this assumption becomes much less reliable when the adversary is a state intelligence service capable of observing internet traffic at multiple points simultaneously.
Wyden’s intervention therefore centers on a distinction increasingly important to cybersecurity: encryption can conceal the contents of communications without necessarily concealing the existence, origin, destination or patterns of those communications.
For Americans considered valuable espionage targets, that distinction could determine whether a conventional VPN represents adequate protection or merely one layer of a much more complex communications security strategy.