in reply to The Matrix.org Foundation

@matrix Mostly the missing authentication of room management messages.

And the underlying issue that the E2EE protocols were all tacked on later instead of made as a whole from the beginning. This makes E2EE extremely hard to reason about implement correctly. The implementations are also hard to use securely by the user.