I should also note that when I say the cryptography in Signal is “probably fine; a practical attack would be a big surprise”, that’s about the best we can say about almost all cryptography used in the real world. No strong (not dependent on unproven assumptions) security proofs for much of anything you’d actually want to use.