Visiting https://superfish.tlsfun.de/style.css pins the valid certs for the domain superfish.tlsfun.de incl all sub-domains. So trying to open https://mitm.superfish.tlsfun.de/style.css should end in a browser error. On Win 7 and Ubuntu 14.04 that actually works: Firefox tells me:
Secure Connection Failed An error occurred during a connection to mitm.superfish.tlsfun.de. The server uses key pinning (HPKP) but no trusted certificate chain could be constructed that matches the pinset. Key pinning violations cannot be overridden. (Error code: mozilla_pkix_error_key_pinning_failure) • The page you are trying to view cannot be shown because the authenticity of the received data could not be verified. • Please contact the website owners to inform them of this problem.
Same for Chrome: NET::ERR_SSL_PINNED_KEY_NOT_IN_CERT_CHAIN
Unfortunately on Arch, Firefox and Chromium/Chrome do load https://mitm.superfish.tlsfun.de/style.css without complaining, i.e. you are not protected against certain MITM attacks. How can this be fixed?