The snooping of unencrypted SNI in the TLS handshake is a known weakness that is still mostly unresolved despite four years of standardization effort. The encrypted SNI work has been revised and updated to encrypted ClientHello and is still technically an IETF draft and not yet formalized in an RFC: https://datatracker.ietf.org/doc/draft-ietf-tls-esni/ That said, CloudFlare, Firefox, and Chromium teams have all been…
And it means that state firewalls will just block all CDNs.
These firewalls are an exercise in having your cake and eating it too.