A prominent US senator is asking the National Security Agency to provide guidance to the general public on best practices for using virtual private networks to secure their communications from spying by foreign adversaries.
VPNs funnel all of a user’s Internet traffic through an encrypted connection to a remote server. The design provides strong assurances that no one between the user and the server can read the encrypted contents. VPNs also allow users to hide their IP addresses from the destination servers they communicate with. While US agencies have previously recommended use of VPNs, none have given recommendations on which ones provide adequate protection.
It’s all in the nuances
There are a host of limitations that can undo many of the protections users may think their VPN provides them. For instance, the encrypted tunnel often terminates once a single server decrypts the traffic and sends it on to its final destination. That means the decrypted traffic or the sending and destination IP addresses may be available for snooping by rogue employees or attackers who hack the server. VPNs also don’t encrypt certain types of metadata, such as time stamps, allowing nation-states to build profiles that can be useful in intelligence gathering.
Source: arstechnica.com

3 Comments
Pingback: Australian science prize awarded to researcher studying memory accuracy of domestic violence survivors - Warsaw.Today
Pingback: Volkswagen confirms it will cut 100,000 jobs by 2030 - Warsaw.Today
Pingback: UN to vote on adopting new world map that shows Africa’s true scale - Warsaw.Today