Signal rolls out automatic key verification with independent auditors

Signal has introduced Automatic Key Verification, a feature that lets users confirm their encrypted conversations haven't been intercepted. The new mechanism is built on a key transparency system that relies on Cloudflare and Trail of Bits as independent auditors.
The system checks that the association between a phone number or username and its public encryption key remains consistent and transparent across Signal's ecosystem. This guards against scenarios where a key is swapped without the owner's knowledge — for instance, if an attacker compromised Signal and linked a different key to a contact's number.
According to Signal engineer Katherine Yen, verifications are performed by the user, their contacts, and third-party auditors, providing the same assurance as manually checking safety numbers. Unlike the old method, it doesn't require an in-person meeting or a secondary communication channel — everything happens automatically.
To enable the new option, users need to go to privacy settings and toggle on Automatic Key Verification. They can also manually check a contact's key via the safety number screen by tapping "Verify Automatically." A successful check shows a green checkmark and an "Encryption verified" message.
Those who don't want to rely on Signal or external auditors can turn off automatic verification in privacy settings and stick with manual safety number checks. The company stresses that the new feature complements, rather than replaces, the existing security system.
Earlier, in May, Signal added warning messages and in-app confirmations to give users time to assess the safety of external requests. This followed attacks by Russian state-sponsored hackers who sent high-profile users fake notifications from Signal's support team.

