> Server-side partial mitigation: use HTTPS (leaking just the host to passive observers)
Does nothing for this case.