That vulnerability applies when accessing normal web pages via Tor.
But that's now what the New Yorker has set up. They're hosting a Tor hidden service, and in that case Tor is necessarily encrypting the traffic end-to-end.
But that's now what the New Yorker has set up. They're hosting a Tor hidden service, and in that case Tor is necessarily encrypting the traffic end-to-end.
Someone between you and that unsecured web page could've changed the .onion address and when you went there you would be visiting a Strongbox hosted by the NSA rather than one for The New Yorker.