Before you say "but I can compile it myself", think of how many people will ever bother to do that.
That's how literally every security person feels about the argument that closed-source software is unknowable.
We don't need decompilers or special tools to read closed-source applications. Almost all of them --- very much including the Signal-based messengers --- are built with tools that produce straightforward easy to follow assembly code.
But that's sort of besides the point. Reading assembly is more tedious than reading C code, which is in turn more tedious than reading Python code. But you don't get to move the goalposts now. You claimed, repeatedly, that closed-source software was unknowable. It is not; it is in fact very far from unknowable. So the idea that Facebook is going to sneak backdoors into some of its most prominent code under cover of "closed source" is an extraordinary claim, requiring extraordinary evidence.
So, I doubt any security professionals would say its preferable to not have the source, but to do the job of verifying the software you have to do it at a lower level than the source anyway, so having the source is a bonus, not a requirement.