"Compared to Telegram (which is also privacy-focused and NOT owned by Facebook like WhatsApp is) that simply works, I'm not sure what Signal brings to the mainstream table."
Firstly, with Telegram asynchronous chats are trivial to make, because all you're doing is managing data the server has using multiple clients. The moment you add E2EE for multiple clients, that's when things get hard, like really, really hard. Try enabling secret chats for desktop client with Telegram and you'll see how convenient Telegram is. See the thing is, Telegram doesn't even have cross-client E2EE. None of the official desktop clients support E2EE, and the 3rd party client that do, are not interoperable with other clients. You don't see the messages on multiple devices.
Telegram is snappier because the team is cheating with the star topology architecture. There's no way to have forward secret, future secret group chats with shared encryption key. There's three choices.
1. No E2EE for groups at all (The Telegram way \o/)
2. E2EE with static group chat key (no forward/future secrecy)
3. Individual encryption of messages to each peer (has both forward and future secrecy) -- the way Signal does it.
So to answer your question "I'm not sure what Signal brings to the mainstream table." Signal brings actual Privacy by Design that Telegram developers have been unable to implement at any point.
"0 POC exploits have ever been released."
That's not what security is about. It's not the researchers with capability to break the encryption, it's the intelligence agencies, and they're not very eager to share.
"They are now recognized as IND-CCA secure"
They sure are. I'm going to be honest with you. I think MTProto end-to-end encryption is fine. It might be even great. You have the fingerprints, you can check there's no MITM. Great. But there's a tiny problem:
1. This great E2EE protocol isn't enabled by default (unlike with Signal)
2. This great E2EE protocol isn't available for group chats on any client (unlike with Signal where all clients support it)
3. This great E2EE protocol isn't available for desktop clients (unlike with Signal)
"To be mainstream, you have to have mainstream usability. Signal does not (at least not right now)."
You might be right in that Telegram is more usable, now. But Signal is catching up and fast, and once the gap closes, every feature will also be an actual feature (one that works privately as opposed to one that has privacy tradeoff of private content having to be shared with the server). At that point Telegram has to implement everything from the ground up.
Also, as for what the Mark Zuckerberg of Russia does with the tens of billions of plaintext messages stored on their server, I have no idea. All I know is that's a really, really, really tempting target for nation state hackers. And I have serious concerns about whether Telegram team would admit their messages were compromised, given that they can't mitigate and promise it'll never happen again by deploying app-wide E2EE: if they had the know-how they'd already done it.
Given that majority of Fortune 500 companies have been hacked, what are the chances Pavel Durov and his team (who lack the capability to implement basic E2EE) have magically hardened their servers against NSA, GCHQ, the Israeli Unit 8200, the Chinese intelligence, the Russian intelligence. Don't make me laugh.
One more thing, AFAIK there's no audit of Telegram's code base, and it's some of the smelliest code I've ever seen: https://github.com/DrKLO/Telegram/blob/master/TMessagesProj/... Look at that file size, the lack of comments, the amount of nesting, the shitty variable naming policy. It's an absolute shitshow. I have _nothing_ good to say about it.
And someone's always posting the Durov's "Why Telegram isn't E2EE by default" propaganda flyer, so here's a refutal before anyone decides it's time to post it again https://telegra.ph/Why-you-should-stop-reading-Durovs-blog-p...