
Signal debuts Automatic Key Verification to stop encrypted chat interception
Messaging app Signal has launched a new feature that lets users confirm their encrypted conversations have not been intercepted, using independent auditors to check encryption keys automatically.
The messaging app Signal has introduced a new security capability called Automatic Key Verification, which gives users a way to check that their encrypted conversations have not been secretly intercepted by an attacker. The feature is built on a key transparency system, a method that lets many independent parties confirm that the encryption keys used in Signal chats are correct and have not been swapped. Signal has enlisted Cloudflare and Trail of Bits as trusted third-party independent auditors to help verify the integrity of conversations.
According to Signal software engineer Katherine Yen, the system works through verifications performed by you, your Signal connections, and third-party auditors. Together these checks provide the same assurance as manually comparing safety numbers, which are codes people can read aloud to confirm their chats are secure. Unlike safety numbers, these new verifications are done automatically and do not require an in-person meeting or a separate communication channel. The system ensures that the association between a phone number or username and its public encryption key is globally consistent and transparent to everyone in Signal's ecosystem. This protects against scenarios where a key is swapped without the key owner's knowledge, for example if a malicious party compromised Signal and associated a different key with someone's phone number.
Users can enable Automatic Key Verification by going to Settings, then Privacy, then Advanced, and toggling the option on. They can also verify the public key of a person they are chatting with by choosing the Verify Automatically button on the safety number verification screen. If the verification is successful, the app displays a green checkmark and an Encryption verified message. People who do not want to rely on Signal or the independent auditors can disable the automatic feature in privacy settings and continue using manual safety number verification. Signal says key transparency offers an easy-to-use way to confirm an important part of messaging security and complements the existing safety number system.
This new feature arrives after a series of phishing and social engineering attacks against Signal users. In May, Signal introduced new warning messages and in-app confirmations to give users time to evaluate the safety of external requests as additional safeguards against phishing, which is when attackers send fake messages pretending to be a trusted service. Those changes were prompted by attacks attributed to Russian state-sponsored hackers who targeted high-profile users with bogus Signal Support alerts that abused Signal's Linked Device feature, a function that lets you use the same account on multiple devices. The attackers were able to gain access to the target's account, chats, and contact lists, according to reports by the FBI, German authorities, and the Dutch government. One month later, the U.S. Department of State announced bounties of up to $10 million for anyone who can help identify or locate members of the UNC5792 and UNC4221 hacker groups linked to widespread phishing campaigns targeting Signal users.
For everyday users, enabling automatic key verification adds a meaningful layer of trust without requiring technical knowledge. It makes man-in-the-middle attacks, where a third party secretly sits between two people and reads or alters their messages, much harder to pull off. For website owners and IT teams, the same principle of verifying encryption keys applies to web traffic: HTTPS certificates and secure DNS resolution ensure that visitors reach the real site and not a fake one. AEU DNS provides private, secure DNS resolution that helps prevent tampering with the domain name lookup process, which can otherwise be abused in man-in-the-middle attacks.
How to Protect Yourself
- In Signal, go to Settings, then Privacy, then Advanced, and turn on Automatic Key Verification so the app checks your chats are secure automatically.
- If you see a Verify Automatically button on a contact's safety number screen, tap it and look for a green checkmark and an Encryption verified message.
- Never tap links or follow instructions in messages that claim to be from Signal Support; Signal will not ask for your account details this way.
- Keep your Signal app updated to the latest version so you receive new security protections as soon as they are released.
- For very sensitive conversations, you can still manually compare safety numbers with the other person using a different channel, like a phone call or in person.