> * if use of this header is picked up widely then we will be headed
> toward a situation where more proxies can relatively safely have blanket
> rejection on CONNECT traffic omiting it, a lot of current day attacks
> will fail, and BCP 188 Pervasive Monitoring stops being pervasive.

I don't believe that anyone who has the capability to intercept and decrypt
traffic will voluntarily give it up.

Since it is trivial for malware to forge this header, I do not believe it
will stop any attacks.

