Based upon what? The download is served via HTTPS, and offers a checksum also secured via HTTPS. Are we entertaining security models in which PKC is considered "not secure"?
Or are we just going by the author's ignorant or disingenuous (depending on how you interpret his words) statements?
Only a bit of transport level integrity. But it doesn't make your average hosting provider into a high assurance one or its servers, OSes, software stacks, etc. Quite known problem since the cryptocurrency era.
Which is maybe why Moxie is encouraging people to rely on Google Play Store.
If you are so concerned about state-level actors that play store is untenable to you, signal and android on commodity hardware are probably not the solutions you want anyways.