Yes, I made a mistake about the key. Adding a key is safe by itself. However by adding third-party repository you are granting Signal a permission to replace packages on your system (unless you manually whitelist package names in apt preferences), and by installing a package from Signal repository you grant it root access to your system.
Sadly debian-based distributions do not respect the principle of least privileges and grant unnecessary permissions to installation scripts.
Sadly debian-based distributions do not respect the principle of least privileges and grant unnecessary permissions to installation scripts.