It's not just timing analysis — look at their long list of difficult measures needed to make these transactions private and ask whether that's remotely plausible for widespread use:
https://medium.com/@tornado.cash/how-to-stay-anonymous-with-...
Very few people are so ideologically committed that they're going to pay extra and live with those constraints, which is a major problem for a protocol which is critically dependent on volume to deliver privacy and repudiation.
> Plenty of people concerned with privacy use public blockchains - you don't need to dox yourself to use them, just need a private key. Unlike traditional finance, where you just have to hope that your PII data won't get leaked one day with all your transaction history.
This is confusing a number of things. Most PII breaches are not the banks but the merchants who collect things like addresses because they need them for shipping or to satisfy legal requirements, and paying with a blockchain won't change any of those needs.
Similarly, very few people have a way to generate and spend a significant amount of cryptocurrency entirely for anonymous online services and will thus need to identify themselves for most transactions — a cryptocurrency exchange isn't exempted from Know Your Customer, companies which have to deal with abuse are going to want to prevent sock puppets or shell accounts, airlines aren't going to lose interest in checking your identity, buying a house without showing where you got the funds is going to attract a lot of attention, etc.
That link to the real world is the common reason why these promises don't pan out. In general, ask yourself how a particular activity would go if you showed up with a suitcase full of cash and refused to say where it came from. Cryptocurrency will be exactly the same in all but a very few cases.