You don't need to be able to decrypt anything to identify an HTTPS flow. An unencrypted SSL/TLS handshake takes place first, before any encrypted data is sent across the wire.

Some firewalls can track this.

Right. But you can still run whatever protocol you like -on top- of SSL.

