I use signal to chat with my wife. I'm glad it offers good enough protection that my country's secret service is whining endlessly that it can't get in. I'm glad our inappropriate jokes don't easily become public.
At the same time, I'm sure that a determined and competent adversary could compromise my phone without needing to break signal's encryption or engineer fairly sophisticated mitm attacks.
I'm fine with that level of security, and don't want a more annoying UI when a device is reset. Because even with the current setup, the chat protocol isn't the weakest link anymore.
Somehow, nearly every article on the subject completely misses this, and instead keeps moving goalposts on reasonable endpoint security.
It also means that an adversary can't go in long after the fact and dig up a message history from a server god knows where.
A lot of the eavesdropping scenarios concocted around key change in particular are fanciful. Practically speaking, end-to-end encrypted chat is often replacing email, not trying to protect secret agents hiding from the Reptilian Council.
Mass surveillance no, but if everybody blindly trusts any key provided (which seems to be the default "setting" for Signal and WhatsApp) then it's easy to start MITM'ing any connection at any point. You'll just get an innocuous-looking "your safety number has changed" and nothing else.
I do agree that it's still much better than nothing but I also agree with TFA when they say that "Signal cut a big corner by not planning device management properly", there are many ways Signal could make it massively easier for users to transfer their keys from one device to an other (for instance by deriving the master key from a passphrase bitcoin-wallet-style, or simply by making it easier to transfer your keys and history from device to device).
Because they didn't do this they probably considered that having an SSH-style intrusive "SOMETHING IS GOING WRONG HERE" message was too annoying and got rid of it. But really, they're fixing the symptom, not the problem.
And I think it's not so binary as care/don't-care about being hacked. You might care a bit, but how much do you care? Just as important, what is your threat model?
Yesterday's hash attack that required $100m supercomputer will require a $10k GPU, which is 5 years will require a $100 GPU. (Not talking about the math changing, but it's been more about weaknesses in S-boxes and other parts of older hash functions that get slowly chipped away)
Similarly, yesterday's system that takes an attacker 3 days to MITM your machine, will take 3 hours, and then will be somebody's python script that installs and aggregates millions of exploits.
So in general, the cost and benefit variables are constantly changing under us.
For those cases where somebody needs more protection, there's a way to go through a little more trouble to use Signal more diligently (agree with important parties not to change keys for a period of time).
To your point though: the cost of executing MITM doesn't just include the equipment, it includes showing ones hand by being discovered.
The big cost of a MITM attack is getting in the middle. The cost of doing the actual attack is minimal.