New: a threat-model-first guide to choosing your network defence, plus the nym-smoldvpn dVPN package and nym-swizzle sender hygiene.
Network
Configurations
VPN

Centralised VPN

IP hidden · P1@L2Req-unlink · P2@L2Local net · P1@L3LGlobal net · P1@L3GFast

Sees

  • VPN exit IP
  • All requests and contents

Can't see

  • Client IP

Residual / countermeasure

  • Within a session requests stay grouped by connection state; across sessions the exit IP re-identifies the client.

Sees

  • Activity fingerprint (no in-transit protection)

Sees

  • Both ends: a single operator can act as a global observer

Pros

  • Fast

Cons / mitigations

  • A single operator sees both ends
  • Add timing and content discipline

Fit

  • Fast IP hiding, but weak unlinkability and a single trusted operator

Verdicts and the latency implied by the path are an illustrative model, not measured values.