Earlier quoted context omitted.
The challenge isn't locating or identifying average users, though, since they'll gladly send you their name and address. The challenge is finding the distributors, who are (presumably) more careful to follow the rules. It sounds like this technique can't really do that in the general case.
Even distributors probably do not know all the ways that Tor can be attacked. Look at the Hushmail/DEA case: you had a reasonably big steroids distributor using Hushmail, sending mountains of incriminating evidence through that system apparently unaware that there was a major security problem. Is it really so hard to believe that the police might be able to get a Silk Road distributor to follow an off-site link?
There are site rules and best practices and distributors are ranked (among other factors) on how well they keep to those. The rules say (among other things) to only communicate through the site, to PGP encrypt any sensitive information, and never to store any information longer than necessary to complete the transaction. I'm not saying there are no possible attacks against that surface, but I don't think the one you've described gets there.
Anyone who breaks those rules puts themselves and their customers at risk. If a distributor got busted because they clicked an off-site link, I imagine the community would say good riddance. And keep trading drugs.