Does this limit who can connect to it anywhere? It looks like it results in an open proxy, albeit with limited destinations. Or maybe there's some "verify peer" type functionality such that clients without the right cert are dropped?
When you set up an AWS EC2 instance (hosts the Squid server) you create "Security Groups" -- effectively a virtual firewall. So unless the instance operator configures an inbound 0.0.0.0 "accept" rule, it will probably be filtered to only accept connections from other instances in your VPC.