Blocking-resistant communication through domain fronting (2015) [pdf]
icir.org
icir.org
Couldn't they just send a redirect, forcing the client to make a second request which would get blocked?
As for the scenario "couldn't the censor send a redirect?" - no. Unless the user trusts the censor's CA (Etilasat or eDellRoot comes to mind), the censor doesn't see inside the HTTPS tunnel, only that it exists to an IP address (looked up by a previous DNS request).
I wonder if this is even possible with HTTP2?