The susceptibility to this kind of attack is a big part of the knock that a lot of people have against HTTPS. It's generally been ignored as "too hard to pull off" - but it's also generally been assumed that your own government won't bother recording your communications without probable cause.
Anyway, unless they were targeting a specific service (which they usually aren't, they usually target a person) it would require too much effort to set this up for all the secure services they use.
If the NSA was to create tons Tor nodes (enter, exit, and relay), the onion may be broken.
Tor is by no means perfect. It is only obfuscating.
It is easy to see how this is broken if you click the TOR button on this thing and then imagine the TOR nodes say NSA on them.
I think it is more fun to imagine security this way (extremely challenging and like you are protecting yourself from the perfect attacker, and the NSA is a good face to put on the perfect attacker). People don't realize how much trust they are putting in their hosting provider, cell carrier, etc.etc. It's insane.
That means that no node knows the source of the traffic, and only the exit node knows the destination.
For the NSA to effectively monitor Tor, they'd need to run a large proportion of the nodes - one paper thought it would require an attacker to run at least one third of the network.
It would be really interesting to determine how much this would cost