> Power users make sure its save for them, if it is, it is save for 'normal' users as well.
Power users can make sure the code they're running is safe for them. There's no guarantee that Signal for example is running the same code they release to others.
None of that addresses the point. Without third party, independent verification of their servers and the code that is running open source provides limited (if any) improvements to privacy and security.
That's part of the point rather than separate. A closed system without any way to prove it's running something often can't to get 3rd party verification or user trust that's consistently believable. An open-source, tamper-resistant system can. Quite a bit of difference. Once verifications come in, the effects of reputation then allow users with less technical knowledge to learn what's trustworthy or not.
For a full solution, it would be a start to what they needed. The main benefit of an open-source server is that people can audit it for vulnerabilities. As in, they get free to cheap labor to reduce their liabilities. People might also submit extensions they find useful. The usual benefits of FOSS for suppliers.
Power users can make sure the code they're running is safe for them. There's no guarantee that Signal for example is running the same code they release to others.