New: a threat-model-first guide to choosing your network defence, plus the nym-smoldvpn dVPN package and nym-swizzle sender hygiene.
Network
Configurations
dVPN · single exit

dVPN · single exit

IP hidden · P1@L2Req-unlink · P2@L2Local net · P1@L3LGlobal net · P1@L3GFast

Sees

  • Exit gateway IP
  • All requests and contents

Can't see

  • Client IP

Residual / countermeasure

  • P2 fails within a session: the tunnel delivers one NATed flow. Across sessions, linkage depends on crowding at the exit IP.
  • Rotate the exit per request to restore P2. See the multi-exit configuration.

Sees

  • Activity fingerprint: WireGuard adds no cover and preserves packet timing

Sees

  • End-to-end flow correlation

Residual / countermeasure

  • The 2-hop route stops a single gateway linking client to destination, but both gateways colluding, or a global observer, can still correlate.

Pros

  • Fast
  • Deployable today

Cons / mitigations

  • A fixed exit is a linking key: rotate per request

Fit

  • The minimum: hides IP; add exit rotation and baseline hygiene

Verdicts and the latency implied by the path are an illustrative model, not measured values.