To elaborate on this, here's an algorithm how to DDoS someone and break the Matrix network at the same time:
* Get a domain
* Get a wildcard certificate
* Spawn a stripped down instance with $randomname.yourdomain.org that can only talk to matrix.org.
* Send a join to #matrix:matrix.org
* Redirect $randomname.yourdomain.org to your target you want to DDoS
* Kill the instance, repeat with another $randomname
Now 2000 - 5000 servers will constantly hammer your target with TLS handshakes.