Signal’s Latest Move: Automatic Key Verification Takes Aim at Man-in-the-Middle Attacks
In a significant step to strengthen its users’ online security, messaging app Signal has introduced Automatic Key Verification – a new feature designed to detect and prevent man-in-the-middle (MitM) attacks. This innovative system uses Cloudflare and Trail of Bits as trusted third-party auditors to verify the integrity of Signal conversations, ensuring that even the most sophisticated attackers can’t intercept or tamper with encrypted chats.
The Automatic Key Verification system works by performing a series of verifications involving the user, their Signal connections, and independent auditors. This multi-layered approach provides the same level of assurance as manually verifying safety numbers, but without requiring an in-person meeting or secondary communication channel. As Katherine Yen, a Signal software engineer, explains: “This system ensures that the association between a phone number or username and its public encryption key is globally consistent and transparent to all participants in Signal’s ecosystem.”
To enable Automatic Key Verification, users simply need to toggle on the feature in their app settings (Settings > Privacy > Advanced). They can also verify the public key of Signal users they’re chatting with by clicking “Verify Automatically” on the safety number verification screen. If the verification is successful, the app displays a green checkmark and an “Encryption verified” message.
The introduction of Automatic Key Verification comes as part of Signal’s ongoing efforts to combat phishing and social engineering attacks. In May, the company rolled out new warning messages and in-app confirmations designed to give users time to evaluate the safety of external requests. This move was prompted by a series of targeted attacks attributed to Russian state-sponsored hackers, who used bogus “Signal Support” alerts to gain access to high-profile users’ accounts.
These types of attacks are becoming increasingly common, with even highly secure apps like Signal being targeted by sophisticated attackers. According to recent research, once attackers have valid credentials, only 37% of their actions are blocked – highlighting the need for innovative solutions like Automatic Key Verification.
As a user, what can you do to stay safe? First and foremost, make sure to enable Automatic Key Verification in your Signal app settings. Additionally, always be cautious when receiving external requests or alerts from seemingly trusted sources. Verify the identity of any requestor before taking action, and never share sensitive information without confirming its authenticity. By being vigilant and using features like Automatic Key Verification, you can help protect yourself against even the most sophisticated online threats.
Source: Bleeping Computer — 2026-08-12