asking for the kind that vpn hides tor and not the other way
i have a framework with whonix in qubes using tor browser (real one i think not brave) and idk if im safe.
i want to use wifi in public (food places and schools) and be hard to spy on and not have anything blocked (videos are blocked). my home network is also phoning home because my family is using a google wireless access point (cant change it they dont like having internet down for more than 5 seconds)
would vpn and tor fix this? should i pick just one? or is there a better way? (all things have to be on device since you cant change someone elses network)


Never use tor with a VPN because it can make you easier to identify on the tor network.
Edit: https://support.torproject.org/tor-browser/general/vpn-with-tor/
Also, it is only fine to use a VPN with tor if you know what you are doing.
i heard you can if you use vpn to hide tor and not tor to hide the vpn
do you mean easier to identify by advertisers, malicious nodes, or isp/gov?
(i dont know what im doing yet)
I use Mullvad + Tor myself from time to time. So I read through the article to understand what issues might come up. Turns out it’s actually advantageous in most cases with a few exceptions. If you use Mullvad (0 logs) and pay through monero/cash/vouchers (no money trail) you’re (slightly) better off.
I’m not sure the topic is really about privacy, but if your threat model requires a VPN + Tor, you’re already screwed.
The government can see the metadata of your requests. With enough metadata they can identify what you’re doing. Adding a second layer doesn’t really change that.
What metadata are you talking about?
They can see the timing and packet size for your requests to the VPN server, as well as what your VPN provider is. On the VPN’s end they can see what sites the users (collectively) are visiting, the packet sizes, and the timing. That information alone is enough to identify who is doing what with reasonable accuracy.
This is before issues of using the government’s massive resources to brute-force encryption, possible government backdoors in VPN servers, and browser fingerprinting.
There are various steps that can be taken to mitigate this, and this of course assuming the government has access to the ISP’s metadata from both your network and the server’s network (not a stretch, but not necessarily guaranteed).