This site uses insecure 1024 bit Diffie-Hellman parameters for Diffie-Hellman key exchange! Please fix!
It would also be nice to disable 3DES ciphers and only allow ciphers with forward secrecy.
[1] http://blog.erratasec.com/2013/09/tor-is-still-dhe-1024-nsa-...