>
Tor [is]
slower than dialup.That was true years ago, but nowadays I rarely percieve any speed difference at all when comparing browsing using Tor and non-Tor.
> Pushing all traffic through a VPN only moves the problem. Now I have to trust some unknown entity in some other country to respect my privacy.
But, and here’s the crucial difference: with VPNs you have a choice. A wide variety of choice. With ISPs, especially in the US, not so much.
> All useful traffic runs over HTTPS already, but metadata is still valuable. My ISP could snag SNI headers and know sites,
That’s due to be fixed with ESNI. Just wait for a technical fix.
> but I don't think they're actively sniffing 100% of the traffic that goes across the wire. No, I think they want to be Verisign/Comcast/OpenDNS and redirect NXDOMAIN responses to ad pages or inject false responses to "unauthorized" queries.
That is true today, but when DoH and/or DoT happens, the ISPs will certainly switch to doing whatever still works. They are merely sniffing and proxying DNS traffic today because it still works, but the second it no longer works, they will switch to whatever does work. You can’t just work around the current mechanisms, you have to look a few more moves ahead.