On September 2, 2026, Sen. Ron Wyden (D-OR) wrote to NSA Director Gen. Joshua Rudd asking the agency to update its public VPN guidance. He attached a Congressional Research Service (CRS) analysis. According to Nextgov's reporting, the analysis concludes that "encryption strength alone does not protect users from an advanced, persistent threat conducting bulk traffic collection." The letter is narrow and technical, but it bears on a live policy fight over age verification and VPNs.
The strongest case for current guidance
NSA and CISA VPN advice has a sound rationale. Most real-world VPN compromises come from unpatched enterprise gateways, not from exotic traffic analysis. Federal guidance therefore stresses patching, multifactor authentication and limiting exposed features. Nextgov reports that this guidance does not address traffic analysis at all. A government that must serve millions of ordinary users could reasonably argue that simple, actionable advice beats a complicated threat model that only a few adversaries can exploit.
What the CRS analysis adds
According to CyberScoop and Nextgov, the CRS analysis says a foreign intelligence service that can observe bulk traffic can match the timing and volume of encrypted data entering and leaving a VPN server. That lets it link a user to particular sites without decrypting anything. The risk is greatest for single-hop commercial VPNs, where one provider sees both who the user is and where they are going.
CRS named multi-hop and mixnet-style tools as more resistant: Tor, Nym and Apple's iCloud Private Relay. These split knowledge of the user and the destination across separate servers. CRS also cautioned that none of them guarantees anonymity.
The letter follows Wyden's earlier VPN correspondence. His March 26, 2026 letter to DNI Tulsi Gabbard asked her to warn Americans that using commercial VPNs may affect their rights against warrantless surveillance. His July 27 letter asked CISA, OMB and NIST to push federal agencies off vulnerable, internet-exposed VPNs. He has asked the NSA for unclassified answers by October 14, 2026.
Why the timing matters
The letter arrives while US lawmakers are pushing more people toward VPNs. The Supreme Court held in Free Speech Coalition v. Paxton, decided June 27, 2025, that Texas's age-verification law for sexually explicit websites faces only intermediate scrutiny. The vote was 6–3. Since that decision, age-verification mandates have spread, and people who want to avoid handing over IDs or biometrics turn to VPNs to get around them.
Some legislators have responded by targeting the VPNs themselves. The EFF documented that Wisconsin's A.B. 105/S.B. 130 originally required covered sites to block users connecting through a VPN. Lawmakers removed that provision on February 25, 2026 after widespread opposition. EFF's core objection was technical: a site cannot reliably tell where a VPN user is located, so it must over-block or impose the restriction nationwide.
The CRS finding sharpens this point. A VPN ban would not make anyone safer. It would remove a tool that, while imperfect, still protects users against many threats, such as local snooping, hostile Wi-Fi and commercial tracking. It would also push people toward less scrutinized services. Meanwhile, the federal government's own analysts are telling Congress that the most common commercial VPN design has real limits against sophisticated state adversaries.
Proportionate policy
There are three sensible steps.
- Update the guidance. The NSA can publish an unclassified, plain-language explanation of what single-hop VPNs do and do not protect against. It should say which users, such as government staff, contractors, journalists and dissidents, face the greatest risk. Wyden's request is the kind of low-cost transparency measure that improves security without restricting anyone.
- Do not ban VPNs to enforce age checks. Blocking VPN traffic is technically unreliable and forces broader data collection. Wisconsin's retreat shows that even sponsors could not defend the provision once its mechanics were examined.
- Reward better architecture. Multi-hop and mixnet designs, and features such as Private Relay, exist because the threat is real. Policy should not penalize them, since privacy-preserving tools of this kind are what CRS points to as more resistant.
The limits of the CRS analysis should be stated plainly. Traffic analysis at scale requires an adversary with broad visibility across network backbones, which is a capability of a handful of states. For most people, a reputable VPN still offers real protection against ISPs, public Wi-Fi operators and advertisers. The right message is not that VPNs are useless. It is that users should match the tool to the threat, and that the government should say so clearly.
The NSA's answer, due October 14, will show whether the agency is willing to say publicly what its analysts and Congress's researchers already understand. Lawmakers debating VPN restrictions should read that answer before drafting more bans. A legislature that wants to protect children online can do so without weakening the tools that protect everyone else.