However, it seems your original data traffic is double-encrypted by both SSTP & SSL. Now suppose that for any reason your SSTP connection is hijacked and decrypted by a third party, e.g. the attacker stole your SSTP password or your SSTP-signed certificate is a fake one.