Yes, Signal’s phone number requirement is bad. But, given that, the fact that they don’t store any messages on their side and everything is client side is still a huge benefit over a lot of other apps and still a huge step forward for privacy! Criticism is definitely important but I just wanted to put that out there that all things considered, Signal is still very much a good thing.
Google Play services are still required for the official builds because of the (unverifiable to be really) encrypted backups.
> everything is client-side
Signal's FOSS fork developers would disagree. They got outright legal problems after they wanted to implement an open source alternative. Most APIs in regards to contact management are server-side. There's Molly as a younger fork but I'm waiting for Signal to write them also a cease and desist letter.
Honestly this is why I think that Signal should be treated the same like WhatsApp. Supposedly end to end encrypted, but only until you suddenly have the FBI with printed out chats in front of your door.
As long as Signal uses proprietary services and contains proprietary blobs in their (default aka Play store-provided) app we have to treat it as an unsecure messaging system.
Especially given the RCEs that it had in the past, where it was as simple as injecting an HTML with a script tag to install malware on your system.