b) And I think this is the bigger issue. People not setting stuff up properly and getting bitten by that.
Genuinely curious, what do you think the average person using Tor should set up to avoid getting attacked? Anyway, I agree with you that they're covering their ass, but more from regulatory pressure than anything else.
Malicious exit nodes mounting MITM attacks is a vector I hadn't considered before. I had been thinking of them mainly as surveillance adversaries. I'm not actually sure this is a legitimate concern, though. It seems like attackers could do more effective analysis on regular clearnet usage to mount more effective generalized attacks on a bigger population.
Maybe DaveF could elaborate on how targeted routing analysis would make such attacks more likely. My initial reaction is that users running NoScript and/or disabling JS should be much better protected against MITM attacks than average web users too, so that's another reason why average TOR browser users should be safer.
This has been going for long, but lately it is ever a concern, as most sites switched to https anyway, and the exit node can do nothing about that.
HTTPS Everywhere is rather useless at this point in time, because, most sites already are https and there is no need to try force it anymore. Besides, those few sites that still don't have https, won't have it magically only because you have that add on. Thanks the EFF for the push tho.
Getting rid of scripts (i like umatrix more than noscript) is a solid move. Only while list trusted sites and at the same time get rid of the tracking garbage.
Be careful when using Tor. Operators maintain a registry of TOR users. That is, just downloading the browser, you get into the list. Files are sent through several servers to confuse those who want to track traffic. The last server in rare cases may be yours. If you're not lucky, "they may be accused of drug trafficking. Most of the Tor traffic comes from the Darknet. Your security and anonymity are at risk on sites without an SSL certificate. It’s better to avoid sites on http and only go where there is https.
This is utter nonsense and you have no idea what you are talking about. Get informed before writing stuff first...