Of course this only helps as long as your device isn't backdoored but that is true for any app.
(I say this as someone who regularly defend Telegram here, because in my opinion I don't have to pick one or another.)
I wonder what the next Crypto AG (CIA front) will be
NSA: VPN and "secure" webmail providers
CIA: They don't need fronts anymore, they have CISCO, Juniper, Netgear, etc.
so yeah if SV firms were not extensions of the US govt. (hardware firms too, not just software), they would have already been broken up years ago.
the senate hearings are just a charade used to stroke the ego's of the 'visionary' SV tech bro CEOs. they also show us how tech illiterate the working class has been made. [2]
[1] https://www.youtube.com/watch?v=6pVfYmttcag, https://www.youtube.com/watch?v=q9oMYL2M_tE
[2] https://www.vpro.nl/argos/lees/onderwerpen/cryptoleaks/2020/...
[3] https://jacobinmag.com/2015/03/socialism-innovation-capitali...
The only semi-popular better option I can think of is Matrix, but getting people on Signal is already hard enough and using Matrix on a mobile device is (last I checked) far from ideal.
Security is a gradient, not an all-or-nothing. Signal is vastly better than almost every other electronic communication method.
- side-load a peer reviewed apk so you can check the sigs and make sure all crypto is being done locally (and to make sure that the implementation is solid)
- manage your own keys like you would with traditional pgp emails. Give your public to your friend. Force them to send anything sensitive using it. Maybe change to symmetric keys from asym but rotate occasionally. But you still have to trust the app you use to do this unless you want to do it manually each time.
*These don't necessarily solve the Metadata issue
Signal has open sourced clients with reproducible builds (on Android) and their encryption library has been reviewed by multiple 3rd parties to great acclaim.
PGP lacks forward secrecy, meaning if a key does get compromised all of your past correspondence is now also compromised.
Edit: As someone that has heard of forward secrecy but not how it relates to pgp, these were helpful reads: