Earlier quoted context omitted.
> Here's how the attack may have happened: Step one, collect data about which computers are sending and receiving large amounts of Tor bandwidth. Step two, if the server resides in a datacenter, request an image of the server. Step three, you now know whether the server is a darknet website. This in itself is not sufficient: there are thousand of Tor bridges, relays and exit points. All of them carry lots of traffic…
Knowing that Tor traffic comes and goes through a server isn't enough. Most data centers would not just hand over disk images just because a server is running Tor and a hidden service. You would need good evidence that the particular hidden service you seek is hosted at that particular data center. They can just enumerate every hidden service, figure out which ones are doing something obviously illegal, then once the…
FTFY