Hacker News new | ask | show | jobs
by mirimir 3369 days ago
Consider CMU's exploit of the "relay early" bug. They identified users and onion servers through compromised entry guards. So with one VPN, the adversary knows the VPN exit IP. If they have authority vs the VPN provider, they get your identity. But if you're using nested VPNs, they need to go after the next VPN provider. Six is probably overkill. Maybe three is too. But it works well enough, so why not?