A new congressional memo has raised concerns that typical, single-hop virtual private networks (VPNs) may not fully protect users from foreign intelligence agencies tracking their online activity. US Senator Ron Wyden has urged the National Security Agency (NSA) to update its cybersecurity guidelines, emphasizing that standard commercial VPNs remain vulnerable to advanced surveillance techniques. The memo, provided by the Congressional Research Service (CRS), highlights that even encrypted data can be analyzed through "traffic analysis," a method used to trace users based on the timing and volume of data sent through a single server. According to the CRS report, adversaries can reconstruct a user's web activity by observing encrypted data flow without needing to decrypt the content itself. This method, known as bulk data traffic analysis, allows intelligence services to determine what websites a user is visiting, even if the data is encrypted. The memo underscores that strong encryption alone does not prevent this kind of surveillance, which is conducted by advanced, persistent threats. To counter this, the analysis suggests using multi-hop tools such as Tor Browser, NymVPN, and Apple iCloud Private Relay. These systems route internet traffic through multiple servers, often in different countries, making it much harder for eavesdroppers to track user activity. Wyden has asked the NSA to clarify whether these multi-server systems are more secure and should be recommended over traditional single-hop commercial VPNs. This is not the first time concerns have been raised about the effectiveness of basic privacy tools. Earlier this week, experts at Proton VPN warned that many users in the US are unknowingly compromising their privacy by using inadequate or free VPN services. These risks are even greater for users seeking free options, as many of these apps are not designed with strong security in mind. Despite these warnings, nearly a quarter of users still rely on free VPNs, a market flooded with applications that often fail to protect user data effectively. Tech companies and government agencies have also voiced concerns about the risks associated with certain VPN apps. Recently, Google issued alerts about some apps that might be disguised as VPNs but actually function as spyware. Cybersecurity researchers also found that both Apple and Google app stores still host hundreds of potentially dangerous links to VPN services. At the government level, authorities have urged users to avoid using personal VPNs on official devices, citing the risks of unauthorized surveillance. As these concerns grow, Wyden's push for updated NSA guidance comes at a crucial time for digital privacy and security.