pretty much spot on, search is still pretty bad on fedi (on the twittery side and the reddity side)
although it is still not hard to invade someones privacy the old fashioned way by, for instance, making alt accounts to evade blocks but thats nothing unique thats all platforms
direct messages arent really private on any platform but on the fediverse they especially arent
not only can your admin read your messages if they really want to (like non federated sites) but also you have to consider the other instances admins too
i think thats why lemmy has a profile field for a matrix username by default because thats at least a more private way to do dms