1. They don't move the goalpost for MitM attacks against SSL handshakes - they eliminate the possibility. Saying that users who would fall for those attacks don't use a VPN is a circular argument.
2. Can your location be tracked outside of IP? Certainly, which is why defense in depth is a thing. But that's a statement in FAVOR of VPNs as part of such an approach.