HTTPS Client Identification Using SSL/TLS Fingerprinting
muni.cz
muni.cz
I don't see a mention of timing in this paper, either. I suspect that it is another viable identifier. After accounting for latency, the speed of the response can give you an idea of what hardware they're using.
It's actually a less intrusive test than say searching the network for SIP end points via WebRTC like used today.