I don't think it's possible, because of domain fronting. 
Domain fronting is a technique for obfuscating SNI. Twitter mangles url, you'll have to take my word for it that it works, and SNI doesn't reveal the contents.
-
-
You're right, google doesn't require SNI match; the extra http:// in the host field was biting me. Cloudflare does require SNI match (tested with openssl directly)
-
Funny thing, I can't get the domain fronting to work with rfc8484. Get an error unless i connect to 8.8.8.8 or 8.8.4.4, then sni field doesn't matter. Trying https://dns.google/dns-query?dns=AAABAAABAAAAAAAAA3d3dwdleGFtcGxlA2NvbQAAAQAB … just something interesting
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.