Bridges still Entry Guards?
3.7. Do we need a second layer of entry guards? If the bridge user uses the bridge as its entry guard, then the triangulation attacks from Lasse and Paul's Oakland paper work to locate the user's bridge(s). Worse, this is another way to enumerate bridges: if the bridge users keep rotating through second hops, then if you run a few fast servers (and avoid getting considered an Exit or a Guard) you'll quickly get a list of the bridges in active use. That's probably the strongest reason why bridge users will need to pick second-layer guards. Would this mean bridge users should switch to four-hop circuits? We should figure this out in the 0.2.1.x timeframe.
That timeframe has come and gone and I did not see any tickets about this behavior (sorry if I missed any!).