Maybe this will help Signal get to a viable solution in a few years.
> Unfortunately, for a reasonably large user base, this strategy doesn’t work because the bloom filters themselves are too large to transmit to mobile clients. For 10 million TextSecure users, a bloom filter like this would be ~40MB, requested from the server 116 times a second if every client refreshes it once a day.
They decided to run computations inside a 'secure' hardware environment instead (SGX specifically) so that they can't get access to the computation themselves but it also doesn't need to be run client side. I assume you meant the former thing, but the approach they actually use is fundamentally different from homomorphic encryption / PIR.
Except, of course, if you put malware in the next build of your mobile app, and grab it before it's encrypted. Which Signal easily could, and it probably wouldn't be spotted for weeks. Fundamentally, it's all about trusting other people.
There's also ZCash [2], which is a cryptocurrency that lets you make untraceable transactions. This is in stark contrast to Bitcoin or Ethereum, where transaction information is available publicly to everyone. They have a series of blog posts [3] on the math that actually makes it work under the hood.
[1] https://ethereum.org/en/developers/docs/scaling/zk-rollups/
[2] https://z.cash