Note that the subject here is talking about what to do in future browser versions, so IE8 never comes into the picture.
This is the wrong level to be talking about this anyways. IPSec is the "right" thing to do, but that ship sailed I guess.
(Obviously the attacker in this case would probably also be able to sniff the requests from the resolver, but still; I'm not making this complaint up or anything, a lot of people have mentioned it before.)
My point is that hostname has always been leaked with HTTP and HTTPS. SNI does not leak any new information.
But that's a red herring. Even if it was all kept encrypted, even if you ignored DNS and reverse DNS, you could connect to the IP yourself.
Yeah, technically there might be more than one hostname, but they're all related hostnames.
Huh? I used to have ~100 hosting clients per IP address, none of whom were in any way related to each other (other than in having chosen me as a hosting provider).