Earlier quoted context omitted.
1. Controlling the exit nodes doesn't mean anything unless they can use it to perform correlation attacks (because TLS, GPG, etc. Exit nodes are considered malicious regardless of who owns them.) 2. Using hidden services obviates the problem of exit nodes.
Controlling just the exit nodes doesn't mean much, but by controlling the majority of all nodes you break TOR. If I controll all nodes your connection uses I can trivially deanonymize you (even if you use hidden services). It has also been shown multiple time that it is enough to control the first and the last node of the connection because timing correlation works great. The upside is that no government would admit…
I have read that research. It works great in a controlled environment without the parallel requests of modern browsers, where packages all arrive in order, and where a high rate of false positives are acceptable. Outside of a lab settings the research gets much more muddy and more speculative that it maybe can be used, but I have yet to see an actually experiment that demonstrate it.