@eevee Yeah, the one thing that really bugs me about cryptography people is that they only, ONLY focus on the cryptography, and act like everything that doesn't satisfy their expectations is a complete objective failure, without any consideration to any other potential exposure vectors that users might actually be concerned about (see also: Signal's still-extant requirement of a phone number to register)
@dragonarchitect @eevee
Not to mention the fact that half of these problems don't exist on Signal simply because there is no federation at all — there is no home server to be compromised as there are no other home servers 😂
@Hyolobrika
As users don't usually audit the cryptographic algorithms themselves and we don't know much about what's happening with these servers, for the most it's "Just trust me, bro!"
Centalised systems are a sweet spot for attacks: you break into one system — you own all the users, but no one might ever get interested in hacking into your server for a dozen users. Centralisation is always weak from security POV — no amount of strong cryptography can change that.