HTTPS encrypts the URL as well as the content of the communication. Someone surveilling the conversation with the ability to observe all network traffic but without the ability to decrypt SSL traffic would be able to tell that the end user had viewed something at a particular website (technically, at a particular server), but would NOT be able to tell WHICH article was viewed.
That's the new key point for 2017 pro-privacy architectures.
Proof of work surveillance doesn't scale because requiring it leverages the disparity between the total level of Internet traffic and intelligence agency resources.
Kill the dragnets as step 1, then worry about step 2.
Edit: What Mike is trying to implement is based on https://arxiv.org/pdf/1512.00524.pdf.
You got it right the first time around, the parenthetical correction is wrong. The SNI is transmitted in plain text during the TLS handshake.
What about inspecting traffic pattern? I suspect that each article has different size.
It still might be a better choice, given that the main domain for many sites goes through CDNs and more complex systems in general, increasing the risk of compromise there (which also would expose network details about the submitter, and possibly even more)? A dedicated securedrop site hopefully has dedicated infrastructure and better security.
Potentially, if they're using TLS/SSL with SNI.
but that's my point... if you're not using SNI, there's only one SSL server on that IP address, and if reverse-DNS fails you, you can connect on port 443 and ask it for its certificate and it will give it to you...
securedrop.ap.org
That still gives away a lot, many of these secure drop sites are on a subdomain.
https encrypts the contents... not things like source/destination often only a destination IP address is required to get URL categories for many Proxy/URL filtering technologies.
So a surveillance agency could e.g. replace the URLs for the various organizations' leaks landing pages and Tor addresses with phishing pages, and anyone who used them would upload documents directly to the agency.
If you mean "transferring over the network", then yes, HTTPS only shows the server you are connecting to, but not the specific URL.
Then again, that can be deduced from the transfer sizes that are still shown.