NetworkThreat ModelConfigurationsVPNCentralised VPN ✅IP hidden · P1@L2❌Req-unlink · P2@L2❌Local net · P1@L3L❌Global net · P1@L3G✅FastL2The destination✅P1❌P2SeesVPN exit IPAll requests and contentsCan't seeClient IPResidual / countermeasureWithin a session requests stay grouped by connection state; across sessions the exit IP re-identifies the client.L3LLocal network observerSeesActivity fingerprint (no in-transit protection)L3GGlobal network observerSeesBoth ends: a single operator can act as a global observerProsFastCons / mitigationsA single operator sees both endsAdd timing and content disciplineFitFast IP hiding, but weak unlinkability and a single trusted operatorVerdicts and the latency implied by the path are an illustrative model, not measured values.UnprotecteddVPN · single exit