New: a threat-model-first guide to choosing your network defence, plus the nym-smoldvpn dVPN package and nym-swizzle sender hygiene.
Network
Configurations
dVPN · multi-exit

dVPN · multiple exits

⚠️

Per-request exit rotation is not available in the Nym SDKs yet. This configuration is planned for a future release. Until then a dVPN client uses a fixed exit, which behaves like a single exit at the destination.

IP hidden · P1@L2Req-unlink · P2@L2Local net · P1@L3LGlobal net · P1@L3GFast

Sees

  • Requests from many exit gateways

Can't see

  • Client IP
  • A complete per-client profile (requests split across exits)

Residual / countermeasure

  • P2 holds given per-request exit rotation plus baseline hygiene. The anonymity set is all clients reaching that destination via Nym.

Sees

  • Activity fingerprint (same as single-exit: no cover, timing preserved)

Sees

  • End-to-end flow correlation (same as single-exit)

Pros

  • The destination sees traffic from all exit gateways, not the client
  • Fast dVPN speeds

Cons / mitigations

  • Only useful when many users share the same exit set
  • No timing protection against network observers

Fit

  • Fast IP hiding with request unlinkability; pair with mixnet for timing safety

Verdicts and the latency implied by the path are an illustrative model, not measured values.