They can always keep the encrypted blobs server side and send the key to the user. But regardless, that isn’t going to help with this issue (see my comment above).