De-anonymization via compromised series of images
I am really sorry to keep bothering you all.
The latest "gossip" on certain boards which has me concerned is talk about a de-anonymization timing attack using a compromised CAPTCHA service (or other service which controls the speed at which a series of images is loaded).
Apparently, they monitor outbound traffic from (I guess all?) known guard nodes, and do timing correlation? No Javascript exploit required, and they don't even need to compromise the target site itself, as long as they control the CAPTCHA it uses. Is there any evidence that this actually works and is being used?
EDIT: This seems to me like a variation on the "classic" correlation attack, described here, which apparently Tor specifically isn't designed to protect against? Or am I misunderstanding?