https://www.whatsapp.com/security/WhatsApp-Security-Whitepap...
https://www.whatsapp.com/security/WhatsApp-Security-Whitepap...
Yes, the signal protocol and signal's implementation are both open source, but you have no way to actually verify that WA has actually implemented the protocol correctly and securely. Sure you could do some basic packet analysis but this wouldn't tell you about the presence of any remotely triggered backdoors.
The only way for you as a user to actually verify the security is by reading the source and compiling the software yourself, or reading the source and verifying the signature via reproducible builds.
I really don't understand the business decision process here. If they just copied Signal with OSS/FOSS code and reproducible builds they would just win outright and tech people wouldn't have anything to complain about. The value of the service is the network anyway -- why care so much about the client?