Encrypted data streams don't look like unencrypted data streams, and so can
be detected.

Wrong. About every JPEG content body or any other well compressed data
are indistinguishable from pseudorandom data, so are encrypted data.

When encrypted streams are allowed only to whitelist hosts, and you don't
whitelist proxies, they become obvious.

Would you allow access to <>?