Skip to content
Tech News
← Back to articles

Signal adds new security feature to thwart man-in-the-middle attacks

read original more articles
Why This Matters

Signal's new Automatic Key Verification feature enhances user security by providing an independent, transparent way to verify encryption keys, significantly reducing the risk of man-in-the-middle attacks. This advancement underscores the industry's ongoing efforts to improve end-to-end encryption integrity and user trust in secure messaging apps. For consumers, it offers a more seamless and reliable method to ensure their conversations remain private and uncompromised.

Key Takeaways

Signal has introduced Automatic Key Verification, a new security feature that gives users a new way to ensure their encrypted chats haven't been intercepted.

The new feature is part of a "key transparency" system that uses Cloudflare and Trail of Bits as trusted third-party independent auditors to verify the integrity of Signal conversations.

"It works through a system of verifications performed by you, your Signal connections, and third-party auditors that together provide the same assurance as manually verifying safety numbers. Unlike safety numbers, these verifications are done independently and do not require an in-person meeting or a secondary communication channel," Signal software engineer Katherine Yen said.

"This system of verifications ensures that the association between a phone number or username and its public encryption key is globally consistent and transparent to all participants in Signal's ecosystem. This protects against scenarios where a key is swapped out without the key owner's knowledge — for example, if a malicious party compromised Signal and associated a different key with your connection's phone number."

Users can enable Automatic Key Verification in Signal by going to Settings > Privacy > Advanced and toggling on Automatic Key Verification.

They can also verify the public key of Signal users they're chatting with by clicking "Verify Automatically" on the safety number verification screen. If the verification is successful, the app displays a green checkmark and an "Encryption verified" message.

Key transparency user interface (Signal)

​Users who do not want to rely on Signal or independent auditors can disable the automatic key verification feature in the privacy settings and continue using manual safety number verification.

"Key transparency offers an easy-to-use way to confirm an important part of messaging security, complementing our existing safety number system," Signal said.

"Over time, this verification, combined with the ones continually performed by your Signal connection and third-party auditors, ensures the consistency of this Signal connection's key across the Signal ecosystem."

... continue reading