The article is from 2014 as indicated in the title. At the time HSTS was not as widespread.
HSTS bypass hacks also exist, which let the attacker controlling the DNS man-in-the-middle you through an insecure subdomain not in the HSTS preloaded list. I’m sure the guy has kept up to date with new developments to keep his job going :)