<tangent opening line of my comment> From people on Reddit: Something that blows my mind- but is fully true
"Hell, I've been in fucking EVE Online alliances that had better opsec than this."
"I'll raise you one: I've never been in any EVE alliance that didn't have better opsec than this."
..I noted Board Games(Secret Hitler, for example) require better opsec. So do card games- it's mindblowing to note this too...
[Main comment by me - technical outlook]
This is not a surprise at all- there were reports that the first Trump administration was using Signal to communicate, and that it was a a risk as messages can be totally wiped and not kept for records keeping.
-From an infosec standpoint- this is more notable than I think people are giving it credit- the fact that the Vice President(Well, maybe not him, he notably admittted in interviews during the presidential campaign, that he'd been briefed by three letter agencies on Salt Typhoon tageting him, but that he was secure because he used Signal) - the director of national intelligence- and several others- use Signal.
it's one thing for Congress, Sweden's Military, and apparently our own military branches to push Signal heavily for non-sensitive stuff-
But when those around three letter agencies -and the groups that would be interested in finding compromises- are using it, that screams to me that it's considered not that easy to attack- which is a point towards Signal
So then the final thing to secure are the endpoints- and of course the risk is a zero day exploit targeting someone. As for subtle push app updates by Signal themselves being a vector- i'd think the Open Source nature of the app prevent that - if the infrastructure for pushing updates is open source as well especially.
Again though- if the White House is using Signal- they likely KNOW most of what their own Three Letter agencies can and can't do(to a point)- so when people in the know are using it- that is telling.
A lot of it may be for the auto disappearing messages, admittedly- but that's notable. And yes, I'm aware Mark Zuckerberg has been known to move conversations off of WhatsApp, to Signal - again, maybe for the disappearing messages(and lack of a report function which would send part of a convo to FB/Meta to my understanding)- but possibly, for the security and lack of meta data being better from a attack surface standpoint