> Jones claimed that IP addresses, and even those of Tor users, are public, and that Tor users lack a reasonable expectation of privacy.
This is an interesting judgment. Tor's purpose is to provide privacy. The fact that it may have vulnerabilities (as all software does) doesn't mean that a person using Tor doesn't expect that it will provide them with privacy.
I think you're conflating two different points. Just because providing privacy is Tor's intended purpose doesn't mean it's reasonable to assume it provides privacy in the 4th amendment sense, when it still involves sending your data to Tor nodes. The argument is that public IP's are inherently not private because you have to give that information up to a separate entity to make any sort of communication. I'd wager that's the "vulnerability" they're referencing - That you don't know who is running the Tor nodes, and by extension can't assume your IP will stay private if you're freely giving away your IP address to them.
By voluntarily giving that information up, there is no reason to expect that the Tor server you're connecting too will keep that information private anymore then a Facebook server would, even if we would like/hope that to be the case. The person who owns the Tor server is well within their rights to keep a log of every IP connected to their server.
You also have no control over the node which makes the actual connection to the outside world - In which case that server can equally log anything it wants about that connection. If the same person controls both servers and puts two-and-two together and figures out you made a connection to website X, they haven't violated your 4th amendment rights because you voluntarily gave that information up by connecting to the Tor network without checking who you were giving that information too.
Tor's intended goal is to provide privacy, but that doesn't mean it gives you a legal expectation to privacy, which I think is what they're getting at. The reality is that third-party entities that can do whatever they want with the data you voluntarily give them - The fact that they're Tor nodes doesn't change this.
Yes, it seems like a rather naive construction. Analogously your email server might have vulnerabilities, therefore you have no reasonable expectation of privacy for any emails you have stored there.
This is an interesting judgment. Tor's purpose is to provide privacy. The fact that it may have vulnerabilities (as all software does) doesn't mean that a person using Tor doesn't expect that it will provide them with privacy.