@august
Per the security paper above, it’s not clear to me that the secret key really •is• secret from the provider at all times.
Regardless, I would expect that the ingress problem means that a very large portion of traffic is available for subpoena in practice.