← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

Signal Introduces Automatic Key Verification to Prevent Man-in-the-Middle Attacks

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Signal launched Automatic Key Verification feature.
  • Uses Cloudflare and Trail of Bits as independent auditors.
  • Verifies public encryption keys to prevent unauthorized swaps.
  • Users can enable or disable the feature in privacy settings.

New Security Feature for Encrypted Chats

Signal has rolled out Automatic Key Verification, a new security feature designed to enhance the integrity of encrypted conversations. This system provides users with an automated method to confirm that their chats have not been intercepted or tampered with.

How Automatic Key Verification Works

The feature operates as part of a 'key transparency' system, leveraging Cloudflare and Trail of Bits as independent third-party auditors. These auditors work alongside user and connection verifications to ensure the global consistency and transparency of the association between a phone number or username and its public encryption key. This process offers the same assurance as manual safety number verification but without requiring in-person meetings or secondary communication channels.

Protection Against Key Swaps

According to Signal software engineer Katherine Yen, this system protects against scenarios where a key could be swapped without the key owner's knowledge. This includes situations where a malicious party might compromise Signal and associate a different key with a user's connection. The continuous verification by users, their connections, and third-party auditors ensures the consistency of keys across the Signal ecosystem.

User Control and Previous Safeguards

Users can enable Automatic Key Verification through Signal's privacy settings. They also have the option to disable it and continue using manual safety number verification if they prefer not to rely on the automatic system or independent auditors. This new feature complements Signal's existing safety number system. In May, Signal also introduced warning messages and in-app confirmations to protect users against phishing and social engineering attempts, following attacks attributed to Russian state-sponsored hackers.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Signal has launched Automatic Key Verification, a new security feature that uses third-party auditors Cloudflare and Trail of Bits to verify the integrity of encrypted chats. This system ensures the consistency of public encryption keys, protecting against scenarios where a key might be swapped without the user's knowledge.