This paper seems to be filled with mistakes and generally stating the obvious for anyone passingly familiar with the protocol and server administration in general.
Even figure 2 / paragraph 2 is incorrect, the cross-signing keys aren't derived, they're encrypted by the master key, which is the only derived key. Then there's stuff like using effectively deprecated database setups and client apps, not disabling debug logs, and so on.
I would not put this as recommended reading lol