In short: US Senator Ron Wyden has sent a letter to the NSA director demanding updated VPN guidance, after a Congressional Research Service analysis he requested found that foreign intelligence services capable of monitoring large portions of internet backbone traffic could potentially link a standard single-hop VPN user to the sites they visit — by correlating the timing and volume of encrypted packets entering and leaving the VPN server. The issue isn't the encryption itself, but the single-intermediary architecture.
What the vulnerability actually is
Most commercial VPN services use a single-hop design: user traffic passes through one provider server, which decrypts it before forwarding it to its destination. If an observer can capture traffic at both the entry and exit of that server — for instance via access to backbone links or cooperation with the provider itself — it can mathematically match packets by send timing and data volume without ever decrypting the content. This is known as a traffic correlation attack, and it doesn't require breaking the VPN's encryption at all.
In a letter dated September 2, 2026, addressed to NSA Director Gen. Joshua M. Rudd, Wyden argues that the agency's current guidance doesn't explain this class of risk to users or draw a clear line between protection from everyday surveillance (an ISP, a public Wi-Fi operator) and protection from a targeted attack by a foreign nation-state.
Who this actually matters for
Wyden stresses that clearer guidance would primarily benefit people facing elevated risk: government personnel, defense contractors, journalists, and human rights defenders handling sensitive material under pressure from foreign intelligence services. For that group, the senator asks the NSA to explicitly recommend multi-hop tools instead of a standard VPN — his letter specifically names Apple Private Relay, Tor, and Nym, where no single operator sees both the source and the destination of the traffic at once.
For the average user who simply wants protection from ISP tracking, public Wi-Fi snooping, or IP-based blocking, a single-hop VPN remains a practical and sufficient tool — the attack described requires nation-state-level resources and backbone access, not a typical adversary.
What this means in practice
The core takeaway is that a VPN isn't a binary "protected / not protected" category — it's a tool with a specific threat model. A single-hop VPN effectively hides your IP address and encrypts your traffic from your ISP, a public Wi-Fi operator, and most local observers. But it wasn't designed to defend against a global adversary that can see traffic at both ends of the connection at once — that threat model calls for a genuinely multi-hop architecture instead.
- Pick a provider with a verifiable no-logs policy. If a provider's server is compromised or subpoenaed, the absence of logs limits what can be correlated after the fact. For more on how encrypted tunnels work under the hood, see our piece on VPN encryption protocols.
- Match the tool to your actual threat model. For protection against ISP tracking, public Wi-Fi snooping, and exposing your real IP address, a standard encrypted tunnel like LiMP VPN is exactly what most people need from a VPN.
- Check for DNS and IP leaks — even a solid VPN is useless if requests slip outside the tunnel; see our guide on checking for DNS leaks.
- For genuinely high-risk situations (targeted nation-state surveillance), treat multi-hop tools as a separate category from your everyday VPN — they solve different problems, and one shouldn't be swapped in for the other.
