> FWIW, I was expecting something like "the mechanism is fundamentally flawed because the e2e encryption actually is designed in a way where the server can derive or find the key"
The mechanism wasn't intentionally designed that way. But the symmetric ChatKeys were created with Random(), seeded (at least partially) with time().