Add NoNewPrivileges=true to systemd unit.

Please consider adding NoNewPrivliges=true to the systemd unit. This will prevent tor from gaining privileges (e.g. by executing setuid binaries).

Trac:
Username: stebalien