Here’s the thing about deniability: even if you successfully remove all cryptographic proof of provenance, actually denying it is still asserting a frame job. That’s useless if the party you’re trying to mislead either is or trusts the data source, like, say, in the case of police surveillance, hackers, nation-state attackers…
I think the real solution to future breaches is ephemerality, which is why it’s critical for any secure messaging service to not only implement all-participant auto-delete, but to also make it easy to opt in to only for specific messages, since that brings the cost:benefit down to a point that it’s actually used.