Trust design: perhaps an invite link shouldn't always be trusted (maybe it's a good idea to ask the user?)

Finally, I think we need a convenient fully-automated key exchange system which is no harder to set up than regular mail.

I trust open-source devs to design something more secure than the ad-hoc solutions end users often come up with.

I realise that this is what Autocrypt and keyservers and so on are about. Allowing such less-secure contacts only for insecure chats, or only for dyadic chats, might encourage scanning.