"There's already an RFC for DNS over TLS, so give it time."

How would that help against an ISP who hijacks the DNS port wholesale (and would likely get a valid TLS certificate)?

