Signal Rolls Out Automatic Key Verification for Enhanced Chat Security
Signal has introduced a new security feature, Automatic Key Verification, designed to bolster the integrity of encrypted conversations. This system leverages a 'key transparency' model, employing independent third-party auditors to ensure chat authenticity and protect against key swapping attacks.

**Signal** has unveiled Automatic Key Verification, a significant enhancement aimed at providing users with a more robust method to confirm the integrity of their encrypted chats.
This new feature integrates into a broader "key transparency" system. It utilizes **Cloudflare** and **Trail of Bits** as trusted, independent third-party auditors, tasked with verifying the authenticity of **Signal** conversations.
"It works through a system of verifications performed by you, your **Signal** connections, and third-party auditors that together provide the same assurance as manually verifying safety numbers. Unlike safety numbers, these verifications are done independently and do not require an in-person meeting or a secondary communication channel," explained **Signal** software engineer **Katherine Yen**.
This verification framework is crucial for maintaining the global consistency and transparency of the association between a phone number or username and its public encryption key within the **Signal** ecosystem. It specifically guards against scenarios where a key might be illicitly swapped without the owner's knowledge, such as if a malicious actor were to compromise **Signal**'s infrastructure and link a different key to a user's connection.
Users can enable Automatic Key Verification by navigating to Settings > Privacy > Advanced within the **Signal** app and toggling the feature on. Additionally, users can verify the public key of their chat partners by selecting "Verify Automatically" on the safety number verification screen. A successful verification will display a green checkmark and an "Encryption verified" message.

*Key transparency user interface (Signal)*
For those who prefer not to rely on **Signal** or independent auditors, the automatic key verification feature can be disabled in the privacy settings, allowing them to continue with manual safety number verification.
"Key transparency offers an easy-to-use way to confirm an important part of messaging security, complementing our existing safety number system," **Signal** stated. "Over time, this verification, combined with the ones continually performed by your **Signal** connection and third-party auditors, ensures the consistency of this **Signal** connection's key across the **Signal** ecosystem."
This update follows **Signal**'s introduction of new warning messages and in-app confirmations in May, designed to provide users with additional safeguards against phishing and social engineering attempts. These measures were prompted by attacks attributed to Russian state-sponsored hackers, who targeted high-profile users with fraudulent 'Signal Support' alerts. These attacks exploited **Signal**'s Linked Device feature to gain unauthorized access to accounts, chats, and contact lists, as reported by the **FBI**, German authorities, and the Dutch government.
In a related development, the U.S. Department of State subsequently offered bounties of up to $10 million for information leading to the identification or location of members of the **UNC5792** and **UNC4221** hacker groups, both linked to widespread phishing campaigns targeting **Signal** users.