Retroshare isn't "like tor", it's "the opposite of tor".
Tor establishes a network of mutual distrust (kinda; you still trust
some aspects of the network such as the directory servers).
Also, I get mixed signals about the developer attitude to some security
aspects of the P2P side of things. For example, they use SHA1 for the
distributed hash table, whereas in my opinion one should never use an
even partially broken hash for a *hash table*; you never know what
exploits are known privately that further break the hash, and should
generally assume it's fully broken if your threat model includes
adversaries like the NSA. If you're willing to compromise on the
quality of the hash that underlies the entire P2P end of the system,
I'm wary about your attitude to security overall.