In addition to what's mentioned in the comments, timing attacks are also possible. If you see what time every packet is sent and received, then you can correlate streams with each other. This is how they figure out who is visiting what Tor websites; you compromise the network of the website, then the network of potential clients, and then you match up the packets. Now they know you visited the website even though you never actually sent a packet addressed to it.
Comments
In addition to what's mentioned in the comments, timing attacks are also possible. If you see what time every packet is sent and received, then you can correlate streams with each other. This is how they figure out who is visiting what Tor websites; you compromise the network of the website, then the network of potential clients, and then you match up the packets. Now they know you visited the website even though you never actually sent a packet addressed to it.