Encryption is just a tip of the iceberg here.
There are several major problems with Signal:
- it is not that private after all since it requires a phone number. Yes, you can override this by using some virtual throwaway number if you are geeky enough but your account will be associated with this phone number anyways.
- as a consequence you _will_ receive spam from bots fanning out messages to phone numbers. You can’t restrict your social circle to allow only chosen people or let’s say people only from your contact list to message you.
- Signal protocol is probably great from the e2ee perspective but it is not federated and unlike XMPP you cannot spin up your own server and have full control over it.
- Since the end product is not a protocol or a framework or a platform it is a product that is run by other people who you can only trust albeit you can verify and audit source code by yourself(or by hiring someone to do it on your behalf). And I am sure you cannot run an end-to-end audit of the whole Signal platform to verify that what they actually run has been built from the source code you have audited.
- Since it is centralized, Signal is prone to censorship in those countries that decide to fight it. This leads to introducing workarounds like this https://signal.org/blog/run-a-proxy/ to help people circumvent limitations in affected regions and territories.