There is a nice little feature in Tor 3.3.1. Maybe we can enable this for users (via torrc.d) running onion services because it will provide considerable protection against guard enumeration.
Major features (onion services):
Provide torrc options to pin the second and third hops of onion service circuits to a list of nodes. The option HSLayer2Guards pins the second hop, and the option HSLayer3Guards pins the third hop. These options are for use in conjunction with experiments with “vanguards” for preventing guard enumeration attacks. Closes ticket 13837.
IFIRC, and AFAIK, that’s why it’s not enabled by default until that problem is fixed, i.e. when the rest of the padding negotiation proposal is implemented: http://jqs44zhtxl2uo6gk.onion/torspec.git/tree/proposals/254-padding-negotiation.txt