I can’t believe they don’t validate a decrypted signature belongs to the user or use a unique encryption key per user/session.