AI News Feed
Market watch
Policy & Regulation

Senator presses NSA for updated VPN guidance; Utah delays anti-VPN age-verification law

Senator asks NSA to update VPN guidance; Utah pauses VPN age-verification law amid challenge.

Wyden sent a letter to NSA Director Gen. Joshua M. Rudd, citing a newly released Congressional Research Service memo that described how foreign intelligence services can trace VPN users through traffic analysis. By matching the exact timing and volume of encrypted data entering and leaving a single VPN server, adversaries can piece together web browsing activity without breaking encryption. "Encryption strength alone does not protect users from an advanced, persistent threat conducting bulk data traffic collection," the memo said. Wyden wrote that Americans facing advanced foreign threats, including government personnel, defense contractors, journalists, and human rights defenders, "deserve clear, honest advice" about protecting their communications from surveillance by foreign adversaries.

Most consumer VPNs rely on a single-hop architecture, routing traffic through one provider's server before sending it to its destination, according to TechRadar. Ars Technica added that the encrypted tunnel often terminates once that server decrypts the traffic, meaning rogue employees or attackers who compromise the server may be able to read the data or observe the source and destination IP addresses. VPNs also leave certain metadata, such as timestamps, unencrypted, which can help nation-states build profiles for intelligence gathering.

The CRS analysis instead points to multi-hop tools such as the Tor Browser, NymVPN, and Apple iCloud Private Relay as safer alternatives, because they split traffic across multiple servers in different jurisdictions. Wyden asked the NSA to clarify whether it recommends those multi-server systems over standard commercial VPNs. Ars Technica reported that while US agencies have previously recommended VPN use, none have given recommendations on which ones provide adequate protection.

In a separate development reported by Fox 13 News, Utah's Department of Commerce said it will not enforce SB 73, a measure that took effect Thursday, until a federal judge rules on a legal challenge filed by Aylo, the parent company of Pornhub. Utah became the first US state to pass a law targeting VPN use as part of a broader crackdown on adult content. The law, framed by the legislature as amendments to the state's age-verification law, says any person physically in Utah "is considered to be accessing the website from this state" regardless of VPN use. It also says website owners that host a "substantial portion" of material harmful to minors "may not facilitate or encourage the use of a virtual private network."

The law stops short of banning VPNs outright, but it makes websites liable for users' VPN usage, a position that has alarmed privacy advocates. "If a website cannot reliably detect a VPN user's true location and the law requires it to do so for all users in a particular state, then the legal risk could push the site to either ban all known VPN IPs, or to mandate age verification for every visitor globally," the Electronic Frontier Foundation wrote in April. "This would subject millions of users to invasive identity checks or blocks to their VPN use, regardless of where they actually live."

SB 73 was signed into law in March and initially set to take effect in May. The first rollout was paused after Aylo challenged the law in federal court; Utah has now agreed again to delay enforcement while the case proceeds. At a hearing on Thursday, the judge said he could not commit to a timeline for a ruling. Aylo and Pornhub have been vocal opponents of age-verification laws, saying the US measures create a "substantial risk" of identity theft and other privacy issues, according to Engadget. Pornhub has blocked access in 25 states rather than comply with the laws.