Yes, that's true. And anyone who cares about the security of their phonecalls should be using encryption rather than POTS; for example, you could use Signal for encrypted phonecalls and SMSes. Warrant or not, unless there's a bug in the implementation, the only way you can tap that communication would be to compromise the endpoints (either electronically, or via a physical bug/tap on the device).