If you're referring to OCSP requests / responses being unencrypted, I would be interested in hearing what your solution to this problem is.
Also, I would recommend that you do not perform any packet captures (as mentioned earlier) to observe your OCSP traffic. You're gonna have a heart attack when you realize that this isn't just an Apple thing and that nobody encrypts OCSP.
Once you understand why, I'd be interested in hearing your new, revised solution.
Finally, it's not quite as bad as sneak makes it out to be. OCSP responses are cached so, as mentioned in TFA (so certificate status is not being checked every time you launch every app), although I'm not sure what the validity interval of OCSP responses from ocsp.apple.com is (and don't have anything running macOS to check). Additionally, I don't see anyone but Apple announcing any part of the 17/8 network (regardless of ocsp.apple.com. being CNAME'd to Akamai).