Earlier quoted context omitted.
ISPs aren't the NSA, and the NSA has no issue watching your VPN egress. SNI is probably the most critical here, and it is getting opportunistic encryption. Threat modeling. Do it.
ISPs rely on DPI equipment vendors, which do all those things. And no, this is not an NSA level stuff, just your basic commercial traffic analyzing. And in fact, the most common spying ISPs do is not on DNS or HTTP, but just on IP sessions, i.e. netflow data, they record and store it for months or years. This is likely the first thing you need to protect yourself from. DoH not just doesn't help privacy, it makes it w…
It's a thing.