>They just decrypt analysis and reencypt and forward. Since communication is not peer to peer and goes via FB the key exchange is prob with Facebook not the users.
Do you have any evidence for this, or is this your "better safe than sorry" assumption for every e2e messenger that doesn't allow you to verify keys?