

Or, if the app has the private key for decryption for the user to be able to see the messages, what’s stopping the app from copying that decrypted text somewhere else?
The thread model isn’t usually key management, it’s more about the insecure treatment of the decrypted message after decryption.
12 is better than 10, I’ll give you that. But 100 is better than 144, and 1000 is way better than 1728.
And that doesn’t even get to 0.1 versus 1/12, or 0.01 versus 1/144.
So 12 might be a better standalone number, but it’s a terrible base to work in.