> While I’d have loved us to have infite manpower getting all the security features in from day 1, we had to bootstrap and we prioritised usable apps over optimising for a perfect spec.
I get the decision. But it leaves a sour taste in my mouth that Matrix advertises itself as "secure" but almost any user is leaking sensitive information without knowing. I suspect that 95% of users would be surprised if you told them about the number of things that leak in E2EE rooms. Probably the better approach would have been to skip pushing E2EE as the default, and disable all insecure features in Element for E2EE rooms (or have an explicit opt-in). The marketing team would hate this approach but it least it is honest and safe.