All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
In a letter sent Monday to leaders at the Office of Management and Budget (OMB), the Cybersecurity and Infrastructure Security Agency (CISA), and the National Institute of Standards and Technology (NIST), Wyden called for a government-wide transition away from "legacy, insecure, internet-facing" VPNs in favor of newer "zero trust" remote access technologies.[1]
"For too long, federal agencies and government contractors have suffered devastating cyberattacks due to their reliance on legacy, insecure, internet-facing VPN servers to grant employees remote access," Wyden wrote.
The Oregon Democrat cited a string of high-profile attacks targeting enterprise networking products, including Cisco, Fortinet, Ivanti, and Check Point devices, and argued that continually patching vulnerable systems is no longer enough.
"The federal government has become trapped in an endless game of 'whack-a-mole' in responding to widespread compromises of legacy remote access technologies," Wyden wrote.
Does this mean consumer VPNs are insecure?
Zero trust isn't a silver bullet
Should you ditch your VPN?
What is Wyden proposing?
Wyden is asking federal cybersecurity agencies to require departments to phase out legacy remote-access infrastructure over the next two years and replace it with zero trust architecture, a security model that continuously verifies users and devices rather than assuming anyone inside a network can be trusted.
He argues that traditional enterprise VPNs create a visible entry point for attackers because they're designed to accept connections from the public internet.
"Legacy remote-access technologies operate a digital 'front door' that is accessible to the public internet so that mobile devices and remote employees can log in," Wyden wrote. "Because these entry points are exposed, hackers can easily scan, target, and break into them."
By contrast, Wyden says modern remote-access systems don't advertise their presence online.
"Instead of leaving an open door accessible from the public internet, modern solutions provide remote access without broadcasting their presence," he wrote. "This effectively makes these servers invisible, ensuring that hackers cannot attack an entry point they cannot see."
Does this mean consumer VPNs are insecure?
Not necessarily.
The VPNs discussed in Wyden's letter are the enterprise systems organizations use to let employees remotely access internal company networks. These typically rely on dedicated VPN appliances positioned at the edge of an organization's network that accept inbound internet connections.
That's different from the consumer VPN services many people use to encrypt internet traffic on public Wi-Fi, reduce tracking, or help protect their privacy online.
The Congressional Research Service memo attached to Wyden's letter specifically defines enterprise VPNs as systems that place a publicly accessible VPN gateway between an organization's private network and the internet, allowing authenticated users broad access once they're connected.
On the other hand, zero trust systems are designed to grant access only to specific applications and continuously verify users throughout a session. They also avoid exposing publicly accessible login gateways whenever possible.
Zero trust isn't a silver bullet
While Wyden argues zero trust architecture addresses many of the weaknesses of older VPN infrastructure, the attached Congressional Research Service analysis notes that zero trust systems have security considerations of their own.
For example, compromising the centralized policy engine that makes access decisions could allow attackers to grant unauthorized access or block legitimate users, particularly if organizations rely heavily on cloud-based providers.
Still, Wyden says it's time for the federal government to move beyond decades-old remote-access technology.
"It is no longer acceptable for agencies to use insecure, decades-old technology," he wrote.
Should you ditch your VPN?
No. Wyden’s proposal targets enterprise VPN systems that businesses and governments use for remote access, not the apps most consumers are using daily.
That said, there are a few steps worth taking to improve your own security:
- Keep your devices and apps updated. Many of the attacks cited in Wyden's letter exploited known vulnerabilities in enterprise software that organizations hadn't fully addressed.
- Use multi-factor authentication (MFA) whenever possible. Even if a password is compromised, MFA adds another layer of protection that can make it much harder for attackers to access your accounts.
- Choose a reputable VPN if you use one. If you rely on a VPN to secure your connection on public Wi-Fi or protect your online privacy, stick with a provider that regularly updates its software, publishes security information, and supports modern encryption standards.
- Be cautious of misleading headlines. News that governments are moving away from certain VPN technologies doesn't mean all VPNs are unsafe.
As organizations continue shifting toward zero-trust security models, consumers can expect businesses to increasingly rely on identity verification, device checks, and continuous authentication behind the scenes.