https://support.signal.org/hc/en-us/articles/360007320771-Se...
If Charlie is selling drugs to Bob and Alice, expiring messages don't help Charlie out if the others are finding ways to capture data on the screen before the message expires (which, is very common for very innocent, non-malicious reasons).
Similarly, though I've not tested this with signal specifically, other chat apps' implementations of expired messages can be futzed with by simply disconnecting the phone from all network connections.
People who need true privacy, regardless of the reason, aren't using chat apps readily available from stores since the apps only prevent passive snooping, they do nothing to help establish circles of trust. Such business is either conducted out in the open without concern for who sees what (you can see this in countless pictures online when people openly sell stuff like weed), or such business stays off chat apps completely because there's no way to validate who is holding the phone on the other end. The transactions occur indirectly using proven safe methods for the courier and buyer (dead drops, mail tricks, etc)
Are you going to insist that this last step, burning the plaintext copy, is not "valid security"? If you do, haven't we so mangled the meaning of security that it's not even intelligible any more?
I believe that "Let's not keep around unencrypted / minimally protected copies of our communications after we're done using them" is a perfectly valid security measure for two people to use. No, it doesn't solve "trust issues", in that one of them could simply refuse to delete the messages, but neither is it intended to.
Ie, use E2EE, use expiring messages, use out-of-band challenge/accept (ie, recipient has to mention keyword or conversation stays plausibly deniable) all seem applicable.
Sort of a reverse survivorship bias at play here.