No, not everything is publicly available. This would steal passwords and “private” messages and more. It would link IP addresses to user accounts, for instance, which provides geolocations of varying precision.
I haven’t thought through the TLS certificate aspect of this though. Perhaps there’s some mitigation to be had there? The current cert expires soon, on 2025-03-24, and covers several domains, including chapo.chat. In any case, I don’t think there’s anything to stop the new domain owner from spinning up new valid certificates for themselves 😓
https://toots.matapacos.dog/@hexbear