As mentioned in my previous post:
They already support encrypted backups. In fact, they don't support unencrypted locally.
> The design is pretty clearly to support the bog standard backup use case of "something happened to my device, I got a new one, I want my old data".
They had, in fact, perfected the local encrypted seamless "something went wrong" workflow - they keys are delivered from the server (stored or generated, I don't know) once you've proved you can receive texts on that phone number. Without that, the local backup is useless.
And IIRC, they ALSO did the same with Google Drive. But then, one day, it stopped counting against your quota and the encryption disappeared.
> I think their design philosophy here is likely "let's err on the side of smooth UX
The UI was as smooth as it can be. It still is, for local backup.
I try not to attribute to malice that which can be explained by stupidity, deadlines or missing budgets, but in this case, there was a decision to remove encryption, that required negotiating with a rival. That decision had costs, and the process had costs. There is a benefit associated or this decision would not have been taken. I don't know exactly what it is.