Earlier quoted context omitted.
They revoked keys of users without giving users a choice, ability to save, backup user messages etc. It is a company with operations, engineering and business ran by amateurs that do not understand the foundation of any user facing business - when you have a choice between not destroying user data and devising a method to handle a situation even if it costs you and losing user data, you do the first. Every single per…
No keys were revoked (nor does Element have the power to do so). What happened was that existing user login sessions were destroyed and users had to log in again. If you had either backed up your keys locally or had an encrypted copy of your keys stored on the server-side as a backup, no access was lost.
1. Send a message to the users with the existing sessions telling them to create backups.
2. Have users confirm that the backups were created
3. Log users that created backups out.
There's no excuse at losing user's data. Ever.