A better blur algorithm (in that it can easily be proven not to be reversible and is faster to process) is to divide the area to be blurred into a small number of cells, (9,16 or 25) get the averaged colour in each cell and then apply an interpolation between those colours as your output. This algorithm is essentially O(n) where n is the number of pixels to be blurred. You can easily prove that the information in the image is at most 3 bytes (each colour) * 25 (number of cells) = 75 bytes which is not enough to encode a face however it may be enough to encode some limited details (such as skin colour, distinctive clothing etc.) so always better to use a black box.
Also I can't help but wonder, in a case like this where you've got the rest of the image, whether the pixels around the border of the blurred region are useful. There's going to be a probability that they're a similar colour to the outer ring of pixels that got blurred, and that might give you enough to start working inwards.
Side note, even with a mere 25px image (effectively) of someone's face I'm not sure if it leaks as little information as you think it does. Just 33 bits would be enough to uniquely identify someone, let alone 75 bytes. Practically you wouldn't be able to recover more than some basic estimates of skin colour and distance between the eyes etc, but in extreme cases that might still too much.
If you redact, say, a credit card number with a blur, and I know what typeface the number would have been written in, and have a reasonable guess as to your blur radius, it might not be infeasible to compare the blurred version of every possible credit card number.
If you redact an email address with a blur, brute-forcing every possible email address will be harder. But if someone (say) leaks information to you, and you merely blur out their address, it's not infeasible that someone else could apply the same blur to a known suspect's email to verify whether it was them or not.
Of course, with a large enough blur radius it's not an issue. Still, a non-zero amount of times, it's been done badly enough I've been able to mostly "reverse" a blur by just squinting and sitting back a few feet.
Always redact text with solid blocks.
I don't know how feasible this approach would be to human faces. I think Signal has blurred it such to make such an attack infeasible.
I also don't think it's sufficient; if you don't want someone to be identified don't take photos of them, full stop and/or period. Take the photo at the top of the blog post. Who on that day, had that a backpack with that type of strap, a blue mask in exactly that shade of blue, that haircut, and that exact BLM t-shirt, in that place at that time of day? That could be sufficient information for a "fingerprint", though maybe not deanonymisation.
Things like swirls can, though: https://thelede.blogs.nytimes.com/2007/10/08/interpol-untwir...
The belief that you cannot identify someone from a blurred face is an extremely strong assumption that is just begging to be demolished using some sufficiently advanced technology.
In particular, if you only need to go from a list of 10,000 candidate persons (thanks cellphone mass surveillance) to three or four candidate persons (shoot them all and let god sort it out) then I am think it is fairly that you could do so with more or less existent technology. (essentially, use machine learning to transplant faces from DMV photos into the scene and then redo the blur and select the most likely matches).
Think of it this way: if you want to winnow 10k candidates down to four people you need to extract less than 12 bits of entropy. It's not trivial because the scene, pose, lighting, etc. make all your measurements noisy and non-independent.
It's impossible to tell from the screenshot, but if they're smart, they should have an explicit degradation step before blurring (e.g. pixelate/lower resolution first).
You can reconstruct a plausible face by deblurring, ie. one that looks sharp and human. But if you want to identify someone having a plausible picture with a pair of eyes in a plausible position doesn't help, you need a fairly accurate assessment of the distance between the correct eyes, and that's susceptible to loss of information during blurring.