I'm not sure that's a fair summary. It's very clearly stated that there is authentication performed after encryption.
The MAC should prevent the remote server changing the counter or any encrypted bits.
The MAC should prevent the remote server changing the counter or any encrypted bits.