New: a threat-model-first guide to choosing your network defence, plus the nym-smoldvpn dVPN package and nym-swizzle sender hygiene.
Network
Configurations
End to end

End to end

IP hidden · P1@L2Req-unlink · P2@L2Local net · P1@L3LGlobal net · P1@L3GFast

Sees

  • Constant-size packets at a Poisson rate with cover traffic

Can't see

  • The peer, the volume, or the activity

Sees

  • Per-packet timing (hampered by mixing and cover)

Residual / countermeasure

  • Long bulk flows weaken per-packet correlation resistance (open question).

Pros

  • No untrusted destination exists, so the L2 adversary is absent

Cons / mitigations

  • Both ends must run Nym
  • Slow (5-hop + mixing delays)

Fit

  • The strongest position: no untrusted destination at all

Verdicts and the latency implied by the path are an illustrative model, not measured values.