The guy's rationale may be kind of dubious but it's clearly stated: there aren't any tools that do DPI on TLS 1.3 sessions right now.
Madness!
socat tcp-listen:8080,reuseaddr,fork 'system:curl $(grep -m 1 GET | cut -d " " -f 2)'
with a little logging to put Nefarious Sites on your Permanent Record.
The protocol must be finalized before enterprise-grade products can use it, not the other way around.