Earlier quoted context omitted.
If you're whitelisting names that point into arbitrary cloud stuff then you're screwed, the bad guys just get themselves co-located so that you'll happily connect to them because hey, this name was whitelisted and so the IP address must be OK. TLS SNI does NOT tell you where the client was trying to reach, you've made a classic security mistake of assuming bad guys are honest. Honest people will truthfully write good…
You are correct that if the bad guy co-locates at the same IP then it is a problem. However that then becomes an issue with the service that chose to host on a shared IP. For other services that use dedicated IPs but spin up/down machines based on load etc it is still much more useful and secure than running a proxy with a CA that generates fake certificates, especially when you can’t update the trust root of the cli…
You're back to seeing SNI requests for cdn12345.catpics.com which happens to be the same as command-and-control.suspicious-site.kp