We don’t really publish a stance on this subject either way at the moment, but I’m thinking we should specifically and actively recommend the usage of a VPN when connecting to Tor.
To be perfectly clear, we would recommend only:
- You → VPN → Tor → Internet
We would strongly recommend against:
- You → Tor → VPN → Internet
- You → VPN → Tor → VPN → Internet
- Any other configuration
VPN providers are simply less suspicious to local network admins because they are commonly used for a variety of mundane tasks like watching Netflix or whatever (thanks incessant YouTube ads!), whereas connecting to Tor directly or via certain pluggable transports can make you stand out far more than you otherwise would to local network monitors.
The counterargument would be that pluggable transports exist which are less detectable to network observers. This is only a transient benefit of PTs/bridges though, because bridges tend to be identified over time, and as such historical traffic to them can be easily identified (more info).
Sending encrypted streams to those bridges on random IPs will stand out more than standard WireGuard/OpenVPN traffic on commercial VPN provider IP space, and they should probably be reserved only for situations where a VPN provider is not an option at all.