But how does that tie in with SNI? The specs say that the client sends the intended hostname as part of the TLS handshake, can the ISP sniff the hostname from that handshake?
[edit] as per wikipedia, https://en.wikipedia.org/wiki/Server_Name_Indication:
The desired hostname is not encrypted, so an eavesdropper can see which site is being requested. This helps security companies provide a filtering feature and governments implement censorship. [..] As of mid 2018, an upgrade called Encrypted SNI (ESNI) is being rolled out in an "experimental phase" to address this risk of domain eavesdropping. On March 1, 2019, Daniel Stenberg stated that Mozilla Firefox supports ESNI.