The thing you're thinking of is true, but there are still speed limits on commercial GPS chips to prevent their use in missile guidance systems. TFA seems to be clearly flouting that law, so, good luck to them.
Would adding a speed restriction in their VHDL that could be trivially bypassed by patching out one line of code satisfy ITAR requirements?
AOSP has this sort of code in it (search for ITAR_SPEED_LIMIT): https://android.googlesource.com/platform/frameworks/base/+/...
I mean there's plenty of prior art with open-source crypto implementations here.