jeroenhd 18 hours ago

For what it's worth, the ISP may not know the search terms entered, but it can see "google.com" followed by "itchybuttcream.net" when people click the first results. The data will grow more granular over time as users click the second or even third result on Google.

On WiFi you control this risk can be mitigated (force DNS to your own server that uses ODoH or similar) but for most people ISPs are still sitting on data gold mines obtained from passively observing DNS.

1
gruez 15 hours ago

They can still get the hostname of the server you're connecting to through SNI, and that's far harder to hide. Most sites aren't using eSNI/ECH.