Right because even with HTTPS, it's possible to know the domain you're accessing, even though you can't tell high individual urls you are accessing. Interesting.
To fix this, SNI extension to TLS was introduced. Now TLS client will optionally send a plaintext domain name it tries to connect to, and the webserver picks a key for that domain. Which is nice but... now the client is leaking their domain name. Encrypted hello in TLS finally fixes this problem.