Tor is a low-latency network by design, so right from the start it gives up some security to be more usable instead. That probably still works against many attackers, including some state agencies, although not the most powerful.
We should also keep the bigger picture in mind. Sure, if the NSA really wants to know everything about you, it's going to keep a record of your outgoing packets, and match it with packets from exit nodes to have all your metadata. But how much is it going to cost? How does it scale? I think we can assume that if everyone were to use Tor, mass surveillance would be at least far more costly. Each new user adds noise in the correlation measures.
I can also argue that if you use Tor from your home or any location that is associated to you in any way, you're not really trying to avoid target surveillance by your government.
So run for office. I would certainly vote for someone who was against this crap.
> It's everyone's civic duty to contribute to the noise
That's a tactic. While it may be useful, a strategy that works to gain political influence is better in the long-run.
No thanks. In my experience, participation inside the political machinery is a waste of time, about as useful as joining the KKK to influence its members to stop lynchings. I think non-violent direct action is a more effective strategy.
Relying on Tor alone to keep you anonymous, especially against nation state actors is probably not a great idea.
Why is it unlikely for them to have that kind of temporal resolution? I would assume the opposite. It seems like it would be trivial to save timing information along with packets. And the timing data must be relatively small compared to whatever data they're saving on the packets, so the added storage requirement is not really a concern.
This isn't to say they couldn't specifically target an endpoint for monitoring, however. Perhaps I was unclear about that.
What a lovely euphemism.
"This sort of attack is powerful, but its applicability to I2P is non obvious" [1]
"Without protocol scrubbing or higher latency, global active adversaries can gain substantial information. As such, people concerned with these attacks could increase the latency (using nontrivial delays or batching strategies), include protocol scrubbing, or other advanced tunnel routing techniques, but these are unimplemented in I2P." [1]