You can sideload (for now) but that forces you to enable "unknown sources" and increase the attack surface on your device, forcing you to reproduce every new release from source by hand to verify it was not compromised... or blindly sideload binaries and just hope your IP address was not served an extra special one.
Moxie -knew- this was a path almost no one has time to use safely and liked it that way. He actively blocked attempts by the community to put Signal in f-droid, so in cases where it is the system package manager, automated signed reproducible builds can be updated painlesssly. By his own admission, moxie blocked convenient and secure community package managers because he wants most installs to happen from Google Play or the App Store so he gets analytics.
In the end Molly made it to f-droid anyway and Signal has no way to stop it, but they actively discourage the use of any binaries they did not compile and cannot track and modify at any time.
Reproducible builds are nice, and I would love to have them for Signal. But I think I disagree with most of what you've written.
Enabling "unknown sources" does not make my device less secure. The setting is also disingenuously named: It is in fact "known sources" I am installing (not "sideloading") software from. It is just not a source Google wants to know of.
I also do not need to reproduce every new release from source. It is a signed APK I'm getting from signal.org.
If the antagonists in my threat model are so capable they could serve a tailored, signed APK from signal.org for the IP I'm using, I should absolutely not use a messenger whose identifier is my phone number, aka my real world identity AND permanent location marker. That feels absurd. A threat actor that capable could just locate me, pick me up and shake me until I unlock the device.
You are saying Molly exists and works fine, so I'm not really sure the whole problematization of Signal holds up. Does the existence of Molly not disprove your criticism that users would have to use the mainline Signal app from the Play Store?
I think it might be a good sign that criticism of Signal tends to presuppose absurdly capable threat actors. It suggests there is little low-hanging fruit left to criticize.