They're presumably not MITMing SSL, so they have access to every host you visit, e.g. foo.com, via DNS. On SSL they cannot see the URL - e.g. https://foo.com/secret
All good points, & my only point was that while we strengthen each link in the chain, we can't assume we're secure while weaker links exist.