I think that the SNI note below is probably the bigger hole.
Example: any traffic to 17.0.0.0/8 = user probably has an Apple device
I think that the SNI note below is probably the bigger hole.