A janny can just manually reset someone's password, get access to keys, and keep messaging people as that person. It will show unverified but if you don't know how it works, you won't think to verify.
So if you do use Matrix, you only want to use one run by a company that you can realistically take legal action against if they lie to you. Why is it federated? It seems like it would be more secure if it weren't.
Matrix seems to be built on compromise at every turn. It wants to be everything and isn't particularly good at anything. It's not bad it's just not good.
RE: https://wizard.casa/objects/019437ea-f138-45e1-a864-89bef69abe70