https://2019.www.torproject.org/docs/tor-manual.html.en#MyFa...
Of course, a malicious relay operator that wanted to increase its chances of being used as both the entry and exit nodes in a single path (and thereby easily being able to correlate traffic between its origin and destination) could add a lot of nodes and not own up to their relationship.
Some people in the Tor community try to watch for relay-creation behavior that they consider suspicious. A common example is a large number of new relays that appear within a short period of time with similar characteristics and don't declare common ownership.
Edit: one of the main tools for this is OrNetRadar, which seems to primarily use the autonomous system number in which the relays are located, as well as the timing of their creation: https://nusenu.github.io/OrNetRadar/
In this case, the relays can be given a flag like BadExit by the Tor developers, which will stop any Tor client from selecting those relays as exit nodes in a path. However, a sufficiently malicious attacker could add a lot of network capacity in a way that isn't recognizably associated as belonging to the same entity, for example by adding nodes in different data centers, with different speeds, with different software environments, and not all coming online at the same moment. In that case, there wouldn't be a way to easily infer that these nodes are associated with the same operator.
As someone has said elsewhere in this thread, there's still the hope that if different organizations add network capacity with malicious intent, they tend to undermine one another's chances of succeeding, at least as long as they aren't directly colluding (because the basic security goal in Tor is that clients choose paths whose constituent relays don't share information with one another).
https://2019.www.torproject.org/docs/faq.html.en#ChoosePathL...
If you're using public Tor nodes, as opposed to bridges, it's not really feasible to prevent nodes from knowing whether they're being used as middle nodes (they can just check whether the previous node corresponds to another node in the public directory consensus).
Experiment A: fire up a baunch of nodes one way, see how many are marked as BadExit; experiment B: vary the way you fire up on one variable (time-delay, node server Os etc.), measure, repeat
By contrast, being marked as a BadExit due to tampering with content can be due to tests whose exact nature isn't disclosed and changes over time, and it doesn't happen instantly, so it might be hard for an individual deliberately malicious exit to deduce which action it took that resulted in the BadExit flag.
Determining whether nodes are secretly colluding (or, equivalently for some purposes, whether their communications can be closely observed by the same adversary!) is a mostly unsolvable problem, and that's an important limitation for Tor's security. There have been some papers that do a statistical analysis about the probability of an individual adversary winning against an individual user, given some assumptions about that adversary's capabilities (what fraction of nodes the adversary controls or observes). Tor has changed its path selection algorithms a bit based on ideas from these papers.
[1] https://metrics.torproject.org/rs.html#search/family:38A42B8...
In short, my reply was: maybe it's not illegal but you might suffer quit a bit by the time it's all cleared.
This is one of those cases where often the question is not whether your actions are legal, the question is whether you can afford the time and resource required, and in some cases take on the potential reputational risk, to successfully defend yourself against someone (commercial, law enforcement, political, ...) who says they aren't and tries to make you stop.
Also I’ve convinced my company to run nodes with their VPS credit. 6 nodes, 30GB per day per node. It costs them 30$.
Most countries allow anyone to setup a company and operate servers. Any government organization with a small amount of resources can setup a front company and turn on a server.
I'll try to find a source when I'm off mobile.
It would definitely be interesting to actually come up with some estimates of how much was being spent in aggregate bandwidth costs, say, 7 years ago, and compare it with what is being spent at present, and see if it matches what would be expected with 'normal user growth' although normal user growth for a relatively niche project like this would be pretty hard to quantify.
(based on my understanding of post-9/11 reality)
https://metrics.torproject.org/rs.html#details/786926E8C497A...