private, authed relays, in foreign, nonaligned jurisdictions, on tor hidden services, the attack surface is social, not technical.
and something you don't mention, is that simplex is able to capture your connection metadata (timing) which is not a trivial value in intelligence, it's much more important to hide that, than to encrypt your messages.
i find the endless wrong-headed game theory analysis of surveillance threats with regard to nostr, to be sad.
the nostr you are talking about, is relay.damus.io and nostr.band and nos.lol and nostr.mom and primal, all full of spam and feds.
the nostr i'm talking about, is my relay, and there is at least dozens of us in the small circle i am in on this network, who also run relays. my relay respects deletes. my relay doesn't send DMs to interlopers. my relay is in spain, but meh. and it's not on tor. double meh.
but it's still not a domestic jurisdiction.
imo, privacy advocacy as it is on the internet at the moment is heavily influenced by spooks, the smell of palantir and the CIA, NSA, MI6, and all the rest are patent to my nose. why is it that mozilla "cares" so much about your privacy anyway? how old are you? does the word "netscape" mean anything to you?
if you are so wise in the ways of cybersecurity, why aren't you discussing the attack surface properly?