I've read the protocol of SimpleX too, but maybe my previous posts were not clear enough: I'm not saying the encryption is weak.
I'm saying it is really easy to feed spoofed apps to target users that bypasses completely any algorithm. You don't even need 5 USD.
