Entire machine traffic via the NymVPN app
Zero-integration fallback: all device traffic goes over Nym in the user's chosen mode. Cannot split sync from broadcast until 3-way app tunnelling ships.
The user selects ONE mode for the whole device (dVPN OR mixnet) — the unavailable path is disabled. Traffic is not split per request until app tunnelling ships (see below).
Whole-device mode: only the selected transport is active — the other path is disabled. Switch modes with the toggle above.
App tunnelling (outside / mixnet / dVPN traffic split)
The user selects ONE mode for the whole device (dVPN OR mixnet) — the unavailable path is disabled. Traffic is not split per request until app tunnelling ships (see below).
Planned app tunnelling directs traffic three ways — outside the tunnel, over dVPN, or over the mixnet — per app rather than one mode for the whole device. Both paths run at once: fast dVPN for block sync and the mixnet for timing-sensitive broadcast.
Latency model
Per-actor assessment (inherited)
The same four threat actors apply. This architecture inherits the assessment of the configurations it implements — one per transport mode (the mode toggle above selects which applies): dVPN · single exit · Mixnet · single IPR. Layer-2 baseline hygiene remains the wallet’s responsibility.
dVPN · single exit
Mixnet · single IPR