Perhaps, I don't know but perhaps, the interwebs is full of the type of misinformation/myths that the deck is challenging, but the reality (which I would assume a chief hacker, ie principal engineer is very well aware of) is that they are neither worse nor better than a plain cookie. I've no idea why you'd store the jwt in localstorage, again this may be an interwebs thing that doesn't reflect good choices. As a cookie-equivalent, you get, for free, a widely implemented abstraction that you learn once and portably apply everywhere. The complexity problem just isn't there AFAICT, and the choices are there for you. With pure cookies, you have to invent everything yourself.
I find particularly puzzling the claim about revocation. The example (p. 47) is a particularly naive implementation, which would scale equally poorly for homemade session ID or jwt.
Based on this visual deck alone -- I make an allowance for audio providing more detail -- I fail to see a well supported argument.
It reads much more as a soft ad for paseto.