HTTPS traffic is actually easier to track
blog.polygraph.io
blog.polygraph.io
We're hoping to encrypt them for TLS 1.3. That's not easy if SNI is needed for the server to know which certificate to use, and nearly intractable if different vhosts have different cipher prefs.
Solutions welcome!