Signal Adds Automatic Key Verification
New security feature prevents man-in-the-middle attacks by verifying public encryption keys, with tamper-evident ledger and independent auditors
Signal has introduced a new security feature called Automatic Key Verification (AKV) to prevent man-in-the-middle attacks. The AKV feature uses a tamper-evident ledger to record changes to user information, such as linked phone numbers, and is accompanied by an index, allowing Signal users to verify the information in the ledger about themselves or their contacts.
The ledger is designed to detect whether someone has tampered with the public keys associated with an account to intercept messages. Signal has developed a new architecture for detecting such tampering, which would require a change to the public encryption key and, in turn, the safety number that a user might not recognize.
To enable AKV, users can go to Settings > Privacy > Advanced and toggle on Automatic Key Verification. They can also verify the public key of Signal users they're chatting with by clicking 'Verify Automatically' on the safety number verification screen. If the verification is successful, the app displays a green checkmark and an 'Encryption verified' message.
Signal uses independent auditors, including Cloudflare and Trail of Bits, to verify the integrity of Signal conversations. These auditors play a crucial role in ensuring that the association between a phone number or username and its public encryption key is globally consistent and transparent to all participants in Signal's ecosystem.
## What it means The introduction of AKV is a significant step in enhancing the security of Signal conversations. By providing an easy-to-use way to confirm the identity of the person you're chatting with, Signal is reducing the risk of man-in-the-middle attacks. This is particularly important for users who rely on Signal for sensitive conversations, such as diplomats, activists, and journalists.
## Why it matters The new security feature addresses a long-standing issue with end-to-end encryption, which is that it is only as secure as the key exchange process. If an attacker can intercept the key exchange, they can compromise the entire conversation. By introducing AKV, Signal is providing an additional layer of security to prevent such attacks.
Signal introduced new warning messages and in-app confirmations in May to give users time to evaluate the safety of an external request as additional safeguards against phishing and social engineering attempts. With the introduction of AKV, Signal is further enhancing its security features to protect its users' conversations.





