@lumi I still think keeping backups forever is mutually exclusive to really using PFS even if you throw away the ephemeral keys and re-encrypt the messages like signal does. But even if you or your contacts have message backups enabled, signal doesn't include view once media or messages that disappear in less than (or equal to?) 24 hours, which I think makes sense and is a nice way to "opt out".
Yes, technically someone could save every message ever sent to them, but if you don't trust someone to play nice then don't message them something you don't want them to keep. No end to end encryption can protect you if the end is malicious.
What I really dislike about element's implementation isn't just that it keeps the ephemeral keys but that element almost feels dark patterny trying to get you to enable it.
@walnut i think it's because of efforts to make sure "unable to decrypt" issues are as rare as possible
but sometimes it is the desirable thing, eg if you are joining a room, all previous messages should be undecryptable
if you log in from a new device, messages from before it logged in should be undecryptable until another client can send the keys and/or history. and even in this case, there really should be a limit there
in general, i find the "store everything on the server forever" approach to be gross, even if there is no e2ee. be hygienic with your data
i tend to be much less icked out by client-side backups however. it's the idea of server-side ones that icks me out. of course the server can store messages for a while for sync or if a client is offline for a while, but not forever