pull down to refresh

This was shared on twitter. The article supposes the MitM attack was state sponsored:
It seems likely that this attack was orchestrated by the state of Germany (or Germany acting in concert with one or more other nation states). There are other possibilities; for example, both Hetzner and Linode might have decided to voluntarily comply with a wiretapping request from a foreign power that was not binding upon them, but this would reflect extremely badly on them, might well be illegal, and seems unlikely.
I've never used xmpp directly but it's an interesting showcase certificate authority vulnerabilities.