the model i'm using for my p2p app toolkit is something i'm calling "anonymous pseudonymity" basically, your identity is an asymmetric keypair that can't be linked to a specific physical device, network address, or location through normal coms so, if you want strong anonymity you can discard your key after every session and/or keep certain keys around to provide a reference persistent or semi-persistent identity

i think basic privacy with random MAC is all you need on a physical mesh, you can't really hide from someone if you are exchanging radio packets. for that same reason, i think it is important to overlay the physical links with an anonymous mix network so you activity on the network is "decoupled" from the packets that you are transmitting

