The mechanism wasn't intentionally designed that way. But the symmetric ChatKeys were created with Random(), seeded (at least partially) with time().
https://ibb.co/T2jmBYr https://ibb.co/1dRfpxQ https://ibb.co/vhdsKp7 https://ibb.co/g7VBX3R https://ibb.co/281zqqj https://ibb.co/SNbYc7k
Indeed, Threema really has to get more credit for this one.
How many people verify their contacts in Signal when they opportunistically get the chance? Wire? WhatsApp? Matrix?
My mother in law wanted to verify keys with me in Threema of her own volition. In Signal, which she tried for the same reason (securely communicating medical data between colleagues), she didn't even know it was possible, let alone that she should be doing that.