if traffic passes under tls shouldn't it be possible to figure out the content or type of content transmitted/received, shouldn't just an ip over tls be enough?
There are some things related to the size and timing of packets that you can use to infer the likeliness of a given handshake inside the TLS stream. The great firewall does similar things to detect Tor. (Not related to the IP-over-HTTP presented above however.)
with this intermediate protocol within tls you're just adding a fixed (or almost fixed) size to the data being transferred and the timing I think is indifferent