How reliable would this approach be if, say, 100x the number of people who currently use TOR start using it?
How reliable would this approach be if, say, 100x the number of people who currently use TOR start using it?
It depends a lot on who the attacker is and what they already know about the user.
Tor's best-case is when someone sees only one side of the connection and has no prior knowledge: the guard node (entry) side sees "who" and the exit side to some extent sees "what", but these pieces of information can't be connected. "Oh, this person's using Tor; no idea why!" or "Oh, somebody's reading French Wikipedia; no idea who!" And that's certainly a huge win for privacy and applies in practice matter to many Tor users every day.
If you have a suspicion about the "who" and you can perform some kind of surveillance against that specific person, or you have visibility into activity on a network where some potential "whos" might be or where the guard node they used is located, the picture gets a lot worse, and it's probably still bad if Tor activity grows a hundredfold. But there are other models where increased use of Tor is just what the doctor ordered, like a government that wants to scrutinize every Tor user.
One paper analyzing how bad some kinds of practical attacks are is
https://dl.acm.org/citation.cfm?id=2516651
but that doesn't necessarily cover the whole landscape for how Tor users' privacy might be compromised.
I'm starting to think about writing a "How Tor Fails FAQ" or something (with an emphasis on the fact that I'm a big supporter, have done outreach on behalf of the Tor Project, presented them with an award, and think the technology is the best in its class). The Tor developers will be the first to tell you that anonymity technology is difficult and fragile.