And I wonder what an estimate is of % of transactions (by volume and value) that are sent from a full node vs public remote node and public web vs tor/i2p.
Obviously won’t be able to get an accurate answer, but one of the remote nodes in that pool might be able to provide some absolute numbers and a rough estimate of their share of connections in that pool.
Should be easy for them to differentiate clearnet vs tor exit node (and dunno how detectable i2p is).
Even the geo-dns mentioned in the article would be interesting data to see geo-source of transactions.
Your own node is connected to other nodes to get latest blocks and publish transactions to the network. These peers are selected randomly among the pool of available nodes. If the attacker has enough nodes, there is a good probability that your node's peers are partly controlled by the attacker. When you publish a new transaction and broadcast it to your peers, the attacker can detect that it is indeed a new transaction (since it is the first time it's seen by the attacker nodes) and that the IP address of your node is the IP address of the transaction sender. It's not going to work 100% of the time (except if _all_ your node's peers are controlled by the attacker) but with a few transactions it's eventually going to lead the attacker to your IP address.
It's the same kind of attacks that are used to deanonymize people on TOR.
If you want to protect yourself from that, you need to add a few layers of trusted no-logs VPN in front of your node, so that the attacker is lead to a dead end.
You're assuming that peers will relay new transactions to all their peers, but that is not the case with the Dandelion protocol that Monero adopted [1].
I suppose even if they controlled all but 2 nodes - the extreme case - even then they couldn't know with certainty which of the 2 nodes sent the transaction, so it could be argued that there is always plausible deniability.
I don’t know which threshold makes the attack practical though. I guess there is probably no threshold: the bigger the share of the network you own, the bigger your percentage of successful IP tagging is.
I agree with what you say about the threshold.
You could craft your transaction and then submit it using a browser on Tor.