pull down to refresh

The important thing is the actual user data is still encrypted and the users have the keys.
Assuming that's all done properly, I agree. Best case though, some nontrivial % of those keys will be phished.
reply