@light @toji You're right, Signal uses FCM which surprises me.
Since Signal is Open-Source, you could see if they tried to backdoor the app. Third party clients can still be malicious, since they have access to your unencrypted messages.