Earlier quoted context omitted.
> I'm not sure how much hiding the SNI would get you in terms of privacy. You could always just look at the destination IP address of the packet. Destination IP will be the same for all sites on the server, SNI tells you exactly which site was asked for. Not meaning to be pedantic, sometimes the distinction isn't clear. But in order to encrypt the SNI name, you'd first need to verify a certificate tied to a bare IP a…
> But in order to encrypt the SNI name, you'd first need to verify a certificate tied to a bare IP address. Why wouldn't a DH exchange be enough?
The DH exchange would be MITMable, but not passively collectable. TLS is (ideally) neither, so DH wouldn't provide an equal level of privacy.
Still, it would be a beneficial extension of the protocol. At the cost of an additional TCP RT.