Disclaimer: am a Tor developer and employee.
Disclaimer: am a Tor developer and employee.
One potential problem is that it's suspected state actors run a large amount of exit nodes.
The community does a lot of active monitoring to kick out misbehaving relays. "Misbehaving" includes running multiple relays without correctly setting the family attribute to identify them as being run by a single entity.
The main danger of malicious exit relays beyond other relays is that they perform some man-in-the-middle active attack. This is largely mitigated by end-to-end encryption. Tor Browser will soon be HTTPS only (other than explicit manual overrides) to help avoid inavertent non-e2e protected connections.
More in another recent blog post: https://blog.torproject.org/malicious-relays-health-tor-netw...
How do know who is the actual real owner behind a machine on the internet?
https://arstechnica.com/information-technology/2013/08/tor-u...
The larger concern for deanonymization is typically flooding the network with relays, since it increases the ability to do e.g. timing-based de-anonymization attacks. This is a bit of an arms race. As @ajvs points out though, the known cases of tor users being de-anonymized were not due to attacking Tor itself, but via other channels. I'm not aware of any known real-world cases of users being deanonymized by attacking or analyzing Tor itself, let alone users being "arrested regularly"