Well, the page is correct. That's the safest way.
I don't know how to verify the SHA fingerprint without Googling (I know how it works, just don't do it often to know the exact openssl or equivalent command).
If I'm downloading the APK directly on the phone, there's a lot that's not under Signal's control that could happen.
What if I'm directly under attack, and I'm trying to move to Signal? The attacker could MITM the connection and intercept the download.
I think that's a fair warning to show a user, because indeed most users will likely want to install apps through Play Store, that'll reduce/remove supply chain risks. Users who know enough about APKs would be able to verify the hash, or build it themselves.
Even if I download the APK, I still have to accept a similar warning when installing it on my phone.