This paper is misleading IMO. The abstract says - "On the positive side, we prove that TLS 1.3 protects the privacy of its users at least against passive adversaries, contrary to TLS 1.2, and against more powerful ones."<p>But if you read the summary, it also says "both TLS 1.2 and TLS 1.3 session resumption present serious privacy flaws despite not using concrete authentication elements, such as certificates ... While [PSK-DHE] provides a measure of backward security, it does nothing to improve privacy."<p>TLS1.3 is awesome, but it's still a layer 4 transport scheme, and there are plenty of ways that a passive adversary can derive privacy sensitive information. I mean it's /trivial/ for a passive adversary to tell that you're visiting an embarrassing website ... to pick just one obvious example.