What does this mean for PG? Should services subject to UK’s IPA or Sweden’s 2020:62 be recommended in certain high-risk categories (like encrypted mail, search engines, browsers, messengers, VPNs)?
I haven’t analysed their client/protocol like @maqp has, but things may or may not be as dire as they were for Apple, as the SimpleX client (&its relays/servers?) is open source.