The "attack" consists of the following steps:
1) Modify the desktop simulator FMS code to support commands in the data protocols (e.g. ADS-B). 2) Send commands through data link to utilize the newly created control channel.
What FAA is saying that
1) It is hard if not impossible to actually inject un-authorized code into an embedded airplane system (FMS, GPS, ...) due to strict quality controls in place. 2) Even if one succeeds with 1) then you still have limits of what FMS can actually do with the plane because it is a separate unit from other systems with well defined protocols (e.g. FMS doesn't control the lights in the plane).
IMHO, the whole "hack" sounds like a BS/PR action. Yes, you can "fake" GPS, ADS-B, and other communication protocols. However, there are other sources of information for pilots (e.g. the old and true magnetic compass) that can and should be used to validate and cross-reference the data. From a pilot's perspective, a "fake" GPS is no different from a "failed" GPS (yes, this happens). One should be ready to deal with this to qualify as a pilot.