Most of the advanced webappsec security features leak information. CSP, HPKP, HSTS, etc, which was all 100% known.
This talk is excellent because it puts together the attacks into real PoCs, real attacks, and great information on how it all works. These attacks in the talk are quality too, instead of being 'mostly' theoretical.
This wasn't really documented all in one place, or as high quality in the past. Way to go @bcrypt. High quality work.