That was the original argument. But Signal has now rolled out functionality (sharing of contact lists and other details with the server through Intel SGX) that does force one to trust the server.
- Hardware
- Firmware
- O/S
- app(s)
- ISP
- internet
- Governments (Yours and Others)
Did you answer 'No' to any?
> E2EE is meaningless if the client and the network are the same
Using modern, networked computers does involve a lot of trust.
But as long as it's not one company delivering the whole stack, some attacks require a gradually more unlikely scenario where a lot of parties across the world would have to cooperate, and the cost of an exploit that traverses the software stack becomes so expensive that targeting you is out of scope.