As per my understanding DFINITY also stores backup of replica states in Zurich(?). Seems centralized and is a breach of privacy. DFINITY also has access to private data of Internet Identity, no?
Nothing is being withheld. The research was published once it was ready for publication. Since then the developer preview was created and released. What is still missing is the production-ready implementation to the ICP protocol. It is a simple matter of prioritization. E.g. tSchnorr was put in ahead of vetKeys because it includes a lot of the building blocks needed for vetKeys. As you can see on the roadmap, vetKeys will be worked on very soon.