Also, it just occurred to me, since all the messages have to go
through the jabber server everything can be captured directly on
the server without having to deal with the encryption.
Since when do you have access to my Jabber server?
And perhaps you miss how application level encryption operates. Even
if you sniff the traffic on the host server it's still encrypted.