But honestly, in a non-open ecosystem, can you really trust that the near-exclusive two major players are actually playing by the rules? Apple has been relatively protective of its users on privacy stuff, but I've lost all trust in Google at this point.
I do! I have a old-ish but up-to-date and stock Pixel phone, and I see (what appears to be) full E2EE with several text contacts in Messages, with ability to verify keys (which admittedly I have not attempted to use yet). It only works if both devices / all of the devices in a group are fully compatible with the version that adds encryption or newer, but when they do, it just starts working automatically and transparently. AFAIK, that's primarily thanks to Google's work.
I think what we've learned from the rise and fate of current alternative messaging apps and services is that, if we actually want to get the majority of the world's population on modern-quality E2EE for all of their communication, it's going to have to be done gradually and transparently through the apps they already use. Getting everyone to switch to a different app is a pipe-dream that will never happen, at least not thanks to the work of any particular person or company.
Apple is pretty good at privacy and security for people playing within their ecosystem. They seem rather indifferent to any attempts to communicate or interact with anybody without an Apple device. Better than nothing, but not great IMO. Google has many faults in many areas, but I think they're doing awesome work at a difficult and thankless job as far as developing a standard for modern and fully encrypted communications that is actually possible for everyone to switch to transparently, and dragging everyone kicking and screaming into actually using it. Apple just rolled out support for it in beta 4 months ago. Very likely in the next year or so, we may see the majority of texts and group-chats between Android and iOS be actually E2EE without the users needing to do anything besides ordinary OS updates. That will be IMO 80% Google's doing, and 20% Apple's.
I am very glad to hear they're finally exposing some of those details though. Now they just need to open it up to third parties, like the original reference implementation did over a decade ago, so we don't need to blindly trust them as much.
I agree that I don't entirely trust Google with all of this power. The problem seems to me to be that every other relevant player in the industry has even less interest in setting up reliable universal secure messaging. Apple is mostly interested in keeping everybody inside their walled garden. The carriers are mostly interested in figuring out new revenue streams in an attempt to get themselves out of the "dumb commodity data pipes while also forced to spend big money on constantly updating nationwide infrastructure" role that the mobile tech world has forced them into. Mobile hardware providers are basically the same, except for hating the "dumb commodity hardware provider of the 13th black rectangle" role. Nobody else's opinion actually matters in this world.
I'd be happy to see them set up their own servers and an actual federated system, it just seems like none of the other players really want to do it.
Long story short somebody preferred to “ship it” instead of waiting to figure out how to make encryption compatible between iOS and Android. I guess there’s some differences in how the key rings work, but Signal can figure it out and /they’re/ open source so it sucks they ever supported unencrypted messages. They just wanted to say it technically worked for rich text messages and reactions.