"The Tor design doesn't try to protect against an attacker who can see or measure both traffic going into the Tor network and also traffic coming out of the Tor network. That's because if you can see both flows, some simple statistics let you decide whether they match up." https://blog.torproject.org/blog/one-cell-enough Work on a client to try and mitigate the risk of timing attacks: https://news.ycombinator.com/ite…
I remember someone at a security conference talking about a kid at a University who sent a bomb threat via Tor. The University simply looked their their logs to see who was connecting to known Tor nodes, narrowed it down by time and found the kid. Source: http://www.theregister.co.uk/2013/12/18/harvard_bomb_hoax_ch...
https://www.defcon.org/html/defcon-23/dc-23-speakers.html#Gr...