If WhatsApp tries to backdoor a channel and one of the users has key change notification, they'll find out about it, and WhatsApp has no idea whether the warning was shown.
If WhatsApp tries to backdoor a channel and one of the users has key change notification, they'll find out about it, and WhatsApp has no idea whether the warning was shown.
The problem is that the might not find about out retransmissions. You are trusting that the "double-tick" means that the message won't be resent, but presumably WhatsApp can indeed retransmit those messages with the new key under pressure from a state actor.
They need to specifically address this point; it's the only thing worth talking about. The rest is just a discussion of implementation of key exchanges generally.
Now it's fair to question whether you can trust the client, but if you can't then there's no limit to what they could do.
"WhatsApp server has no knowledge of whether users have enabled the change notifications, or whether users have verified safety numbers."
If it's off by default, then the answer is likely to be near zero, as it often is with default options. This isn't an argument about the security of the app (which I have no background to know), more of a comment on relying on non-default behavior.
Even if you enable the key change notification, it is "non-blocking" in WhatsApp as outlined by the blog post: when you get the key change notification, the WhatsApp client will automatically without user intervention resend undelivered messages (unlike Signal, btw, from what I understand).