http://yw7nc56v4nsudvwewhmhhwltxpncedfuc43qbubj4nmwhdhwtiu4o6yd.onion/t/why-we-abandoned-matrix-the-dark-truth-about-user-security-and-safety/224
However, a malicious admin can simply add a new device on a user’s account, thus allowing the sending and receiving of e2ee messages. In most clients, this will show up as an unverified device, resulting in a red shield icon to be added in the room to showcase the presence of the unverified device.