For instance, the claim that modern cell protocols can be "silently" MITMed is not really true; the current known attack to spoof a GSM tower, I believe, is limited to using some vulnerabilities in older GSM protocols, and may not work against modern 3G or LTE. And, indeed, the paper cited on a cryptosystem in GSM 3G being weak enough to pull data off the air does not say that at all: it simply weakens the cipher, but the conclusion of that paper itself says that the attack may not be viable for current networks.
The author's view of how the UID works in the Secure Enclave is weak at best, as well. The article that the author cites the possibility of the "Secure Enclave code being able to read the UID key"; as comex mentioned yesterday [1], this isn't true. (I know also that other SoCs work the same way that comex mentions; this is a common pattern.) The author then goes on to discuss what could be done even if the key bits were extracted from fuses (an attack that I agree is possible); he claims a cycle time of 800 per iteration if executed on a CPU, but in reality, the encryption is done on a dedicated AES engine; I believe a cycle time closer to 4 per iteration is more likely, giving timescale estimates over 2 orders of magnitude worse than the author suspects.
It's not all bad, though. The author makes at least one very good point: 0day on the device, while it is powered on, could be enough to simply run the entire device through the onboard crypto. The exploit doesn't need to be complicated enough to modify the system software permanently -- as long as it can be used once, that's good enough.
I think the crux of the matter is that this crypto scheme is not designed to stop the NSA, anyway: it's designed to stop comex and to stop the local police. If you need an NSA-proof device, you need a much much smaller attack surface to begin with.