Earlier quoted context omitted.
Yup. Hashing phone numbers is basically useless. If they truncate enough there might be plausible deniability due to possible collisions but I suspect the chance of collision is still quite low as they don't want to annoy people with false positives.
False positives would be sent to the device for local comparison against full hashes; it wouldn't "annoy people" because it would not trigger a match unless the full hash matched on device. There is indeed a way to truncate enough to balance the amount of data sent to the device vs privacy.
I missed that option (basically now the Google Safe Browsing API works) and the Signal page isn't clear that this is how it works.