What security? They care about metadata and metadata only. Even E2EE messages provide the following metadata back:
- Phone numbers of senders and recipients
- Timestamps of the messages
- IP addresses or other connection information
- Sender and recipient's mobile carriers
- SIP, MSRP, or CPIM headers, such as User-Agent strings which may contain device manufacturers and models
- Whether the message has an attachment
- The URL on content server where the attachment is stored
- Approximate size of messages, and exact size of attachments
Signal, on the other hand… collects time last active and phone number. That’s security.
What can be done with that metadata? You can construct exactly what the messages contained, without ever reading a single message.