In our customer base, the biggest driver to deploy MitM is the refusal 
of browsers to display block pages from denied CONNECT requests.

>>of course, IP-over-DNS is a typical desperate tunnel of last result to 
>>https.. combined with dns over h2 that could give you
>>I'm sure that would be totally fine from a congestion and flow control 
>>pov :(
>It would be *so* much more productive to try to tackle these problems
>as the political human-rights issues they are, than stacking boxed 
>and higher trying to cross over the walls people erect.
>The one sure result from tunnelling more and more through HTTPS is that
>HTTPS will be MiTM'd and blocked more and more.
