TechNewsReel
Live

Signal launches Automatic Key Verification to thwart man-in-the-middle attacks

The encrypted messaging app introduces a transparency server and third-party auditing to automate the verification of public encryption keys.

TechNewsReel Newsroom · August 12, 2026

Signal has launched Automatic Key Verification (AKV), a new security feature designed to prevent man-in-the-middle attacks by automating the verification of public encryption keys. The update ensures users are communicating with their intended recipients without requiring the cumbersome manual exchange of cryptographic fingerprints.

The new system utilizes a key transparency server and a globally consistent map of public keys to validate identities. To prevent the server from becoming a single point of failure or a tool for deception, Signal has partnered with third-party auditors Cloudflare and Trail of Bits. These auditors verify that the transparency server has not been tampered with and provides consistent data to all users. According to Signal, the security model relies on a dual approach: auditing guarantees that two users are looking at the same data, while monitoring ensures that both parties regularly check that data for accuracy.

The vulnerability of centralized keys

Signal is a primary tool for high-risk users, including journalists and diplomats, due to its robust end-to-end encryption. However, a theoretical vulnerability exists in how centralized directories distribute public keys. In a man-in-the-middle attack, a compromised directory could provide a user with an impostor's public key instead of the intended recipient's. While messages remain encrypted, they are encrypted for the attacker, who can then decrypt, read, and forward them without the users' knowledge.

Previously, Signal users could mitigate this risk using "safety numbers"—cryptographic fingerprints that must be compared manually. While effective, this process is rarely performed by the average user, leaving a gap in the security chain that AKV is designed to close.

Why transparency matters

By introducing transparency logs and independent auditing, Signal reduces the amount of trust users must place in the company's own infrastructure. The shift toward a verifiable ledger means that any attempt by a malicious actor or a compromised server to intercept communications would leave a detectable trace in the public record.

This move aligns Signal with a broader industry trend toward "key transparency," where the goal is to make the distribution of encryption keys publicly verifiable rather than relying on the blind trust of a service provider. For the end user, this means a higher guarantee of privacy without sacrificing the convenience of a seamless chat experience.

How to use AKV

Users can trigger the new verification process by navigating to a contact's profile, selecting "View Safety Number," and tapping "Verify automatically." Once activated, the system checks the transparency server to confirm the key's validity.

While the rollout marks a significant step in securing encrypted communications, the system's efficacy depends on the ongoing vigilance of third-party auditors and the accuracy of the monitoring process. Users should continue to monitor their safety numbers for unexpected changes, which may still indicate a change in device or a potential security event.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.