They could also handle this by routing packets from different customer tiers to different hosts that all handle the same TLS hostname. Or, even, to different interfaces on the same Netflix CDN box they have sitting in a local rack caching everything. That wouldn't break TLS, because all of those hosts work as a TLS endpoint for the same host.