That's one of the reasons I like this talk so much. It really cemented these type of issue with real attacks, instead of a loosely described bunch of PoC. I remember reading somewhere on an RFC (perhaps CSP) that reporting can cause unwanted information leakage, but I didn't find it in the security considerations with a quick control+f just now.
[0] - https://lists.w3.org/Archives/Public/public-webappsec/2015Ju...
[1] - http://homakov.blogspot.com/2014/01/using-content-security-p...