This was published in 2015. Updating to a more recent firmware, which requires a PIN when computing the public key, eliminates the utility of such an attack.
As jochen mentions in his timeline in the post trezor asked he delay publication until they could fix the bug in release 1.3.3. he says they included a fix on Mar 30 which you'll find in the link above