The title is clickbait. There are no exploits involved. He's not dropping NITs on users, for example. Fingerprinting is not a huge issue. The main defense is preventing adversaries from learning one's ISP-assigned IP address. Maybe Tor Project does encourage too much confidence in the "all users look alike" feature. They certainly do, in my opinion, regarding the security of Tor browser in Windows, with no protection against exploits and Tor bypass.

