Unless I'm misunderstanding the docs, the webRequest permission isn't going anywhere, just the webRequestBlocking one. So it doesn't sound like there has been any security win here.
Yeah, I think you're correct. The security win is that you can block without needing the permissions for webRequest which are "can read and modify everything you do"