Questions about what methods investigators can legitimately use aside, the practical implications are clear. You can not count on Tor alone for real anonymity. So what might these NITs be doing? In the simplest case, they'd be dropping malware that reports ISP-assigned IP address, local IP address, network hardware MAC, and whatever to FBI servers. And it's probably Windows malware. To protect against that, you isola…
This applies as well to people who run Tor hidden services that are doorkicker bait (like drug cryptomarkets).
It should be impossible for a compromised browser or hidden service server or Tor process to know anything about your hardware or MAC address, your internal IP address (the RFC1918 one), or your globally routable IP address.
also yeah the Feeb loves to exploit browsers (especially firefox :^) and make them execute the NIT (which just sends, unencrypted/unauthenticated data of the MAC address, ethernet interface's IP addresses, username, and stuff like that, to a computer run by the FBI)
once one of their exploits got leaked, it was pretty fucking lulzy https://blog.mozilla.org/security/2016/11/30/fixing-an-svg-a... https://lists.torproject.org/pipermail/tor-talk/2016-Novembe...