@mmn
> Have a look at XMPP for proper privacy and security.
I don't get this argument, and I've seen several people make it. Without E2EE, XMPP or email is no more inherently secure than OStatus+mastoflags or AP.
It's just that we don't have an existing base of implementations that put your XMPP or mail conversations on the web. That's a valid argument, but one cannot make it in the same breath as "[all it takes is one malicious Masto instance]" or "[the web is inherently insecure]".
Security in XMPP and SMTP is just as bolted-on as any other except those E2EE-from-birth protocols where e.g. your pubkey is your identity.