Looking at the latest Tor Browser Bundle (2.4.17-beta-2):
> it's trivial to break Tor IP address anonymity, as described on the Tor website, through the use of Flash, Java, and add-ons that bypass the typical port proxy
The bundle doesn't ship with any plugins enabled, the only plugin included in the package is Flash, and if you try to enable it it displays a warning explaining the risks and asking for confirmation before continuing.
The only extensions it ships with are HTTPS-Everywhere, NoScript, the built-in Firefox PDF viewer and Torbutton.
> HTML tags that call out to FTP bypassing the standard web ports
FTP connections on the Tor Browser go through the proxy, same as HTTP connections. You can test this easily enough by looking at Vidalia as you open an FTP connection. Also the site makes it clear that FTP outside the Tor Browser must be manually configured to go through the proxy (https://www.torproject.org/docs/faq.html.en#FTP)
> Tor traffic relies on an exit node, operated by an unknown person, that can sniff your unencrypted traffic
Tor provides anonymity, if you decide to pass unencrypted traffic through it, it's your responsibility. The site makes this clear enough (https://www.torproject.org/download/download-easy.html.en#wa...)
I'm not sure what to make of the rest of your argument, that companies such as Google have incentives not to abuse your privacy, while it's been show time and again that their only choices are to comply with secret government surveillance orders or shut down. Somehow, I think their incentives fall on the side of making money so I doubt they'll choose the latter. I mean, think of the poor stockholders left high and dry.