If I had endless resources and was truly paranoid, what I'd do is build my set of public guard nodes, make sure they're serving Tor traffic, etc. But then, I'd "borrow" those IPs occasionally for trusted nodes which will only accept connections from me (ideally both sets of machines will be live and routing traffic simultaneously).
In theory, you could apply the same tricks with similar success to exit nodes of course (though as usual, running an exit node is generally a slightly riskier / harder thing to do)
If they do all you've done is made the middle mode the guard.
That's not how Tor nodes work. Once you setup a guard node (and it got enough reputation) you won't be the only person using the guard node. Also de-anonymization attacks require you to know the traffic coming to the guard node (and if you run a trustworthy one yourself and you're not dealing with a global passive adversary then there's no way the attacker will be able to see the incoming traffic to the guard node).
That's not how Tor nodes work. Once you setup a guard node (and it got enough reputation) you will NOT be the only person using it.
I guess this approach works fine for an individual, but if everyone has to run their own guard node to be safe, why would anyone connect to your guard node (given it would be risky from their perspective since they aren’t running it themselves).
In other words, if you accept you can’t trust anyone else, why would anyone else trust your node too?
(Edit: Sorry I’m wording it poorly but I hope you get the idea)
By the time a few percent or tor users are running a guard node, KAX17 would be too diluted to be a real threat.
Does an attacker only need to control the guard and exit nodes, or the middle relay node(s) as well?
If the latter, can you configure Tor to use more than one middle relay node, depending on your threat model?
Could Tor do something like overlay a fixed-throughput circuit-switched network on top of the packet-switched network to prevent correlation attacks? Obviously at the expensive of efficiency.
Also: If KAX17 is running nodes on 50+ AS's "including non-cheap cloud hosters like Microsoft" shouldn't it just take one insider at one of those hosts to leak the identity of one or more of these node operators? Come on, guys...
No, only controlling the guard and exit nodes is necessary.
> If the latter, can you configure Tor to use more than one middle relay node, depending on your threat model?
Tor makes dozens of circuits in a typical use. You never stick to a single circuit. In the Tor Browser you have first party stream isolation so you get a different circuit (and hence different middle and exit nodes) for each first party domain that you visit.