Working out what website I'm browsing by doing packet analysis between my client and an IP address is vastly more difficult than just reading "www.pornhub.com" out of the SSL handshake. Despite what you think, it's not "pretty easy".
Just because a security control doesn't mitigate all risks against all threats doesn't mean it's not useful.
Like, build a prototype, show it works for some set of things Cloudflare offers over eSNI today.
Otherwise this claim is hollow. If it isn't more difficult then it sure is weird that nobody does it.
Let us know how expensive "not more difficult" ends up being. It'd be great to know that DoH plus eSNI made things "Not more difficult" by say $5M per target. I'd call that more difficult but I know you disagree.