Until we get rid of SNI[1] in HTTPS for good there will still be providers (like my ISP) that do deep packet inspection on SNI and kill the connection right away if you happen to visit a forbidden site (and this was western Europe, yesterday, on a site behind CloudFlare) [1] https://en.m.wikipedia.org/wiki/Server_Name_Indication
You can bypass SNI inspection [0] with tools like GreenTunnel [1] and Intra [2]. [0] https://twitter.com/vinifortuna/status/1304189371688660992 [1] https://news.ycombinator.com/item?id=22654737 [2] https://getintra.org/
E: NVM, found it. It does like it uses split hellos.