Also, the tool seems to perform an online attack with the phone connected, which means that Apple will be able to stop this from going on.
Seing that only an online attack can be done hints at the fact that the key derivation method that turns the 4 digit passcode into the AES key isn't known (yet).
I'd say that you are (still) pretty save if you use the longer password instead of the passcode and as long as the tool requires the phone to be connected, we can count on Apple patching the issue.
It's funny how these articles always talk about having "cracked the AES encryption" when all they do is brute-forcing a password.