Signal adds an extra layer of security to make sure you’re actually chatting with the right person

← Back to the feed

Signal adds an extra layer of security to make sure you’re actually chatting with the right person

The Register · 11 hours ago

Signal has introduced Automatic Key Verification (AKV), a new feature designed to protect against man-in-the-middle attacks in which someone could intercept encrypted messages by tampering with the app's central directory of user accounts. The update matters because Signal is widely relied upon by diplomats, activists and journalists for secure communication, and while its end-to-end encryption already scrambles messages, a compromised directory could previously have redirected encrypted chats to the wrong recipient without users noticing.

AKV lets users tap "Verify automatically" on a contact's "View Safety Number" screen to get a green checkmark confirming their public encryption key matches what Signal's new key transparency system expects. Behind the scenes, Signal logs every account change, such as a new phone number, into a cryptographic ledger and index, which it checks on the user's behalf; independent auditors Cloudflare and Trail of Bits verify that this ledger itself hasn't been tampered with, though a monitoring step is still needed to confirm the underlying data is accurate. One notable limitation is that the feature currently requires having a contact's phone number.

  • Signal launches Automatic Key Verification to block man-in-the-middle attacks
  • Users get a one-tap green checkmark confirming a contact's encryption key
  • Cloudflare and Trail of Bits independently audit Signal's new key ledger

Software

Read the full article at the source →