Reminds me of a slide from one of Peter Gutmann's lectures on PKI and related stuff: a mock up of a title page for a proposed conference paper, titled "Do SSH Fingerprints Increase Security?", with abstract consisting of just "No."
Yes, it follows other slides that describe precisely the attack in TFA, only for traditional SSH fingerprints, and the real world surveys on the "how many users have called or emailed to verify the SSH key fingerprint whenever the key changed?" question (answer: literally zero), so it seems sadly accurate.