🔒Signal Launches Automatic Key Verification for Secure Chats
Signal's new feature makes key verification easier and safer
TL;DR
Signal's Automatic Key Verification simplifies secure chat setup by verifying public keys without direct safety number comparison. It uses external auditors to ensure key transparency and security.
Signal has introduced Automatic Key Verification, a feature that simplifies the process of verifying public keys in secure chats. Previously, users had to manually compare safety numbers with contacts to ensure message security. Now, Signal performs periodic self-checks and fetches Merkle tree heads from auditors to validate key consistency. This feature enhances security by making it harder for attackers to hide key mismatches. Users can enable it in settings and verify automatically in supported chats.

Key Points
Automatic Key Verification requires signatures from three auditors to validate key consistency.
Signal periodically fetches Merkle tree heads from auditors to verify key maps.
Auditors sign the head of the Merkle tree using a unique signing key, ensuring consistency.
Users can enable Automatic Key Verification in Signal's settings under Privacy > Advanced.
Automatic Key Verification warns users if key verification fails or is unavailable.
Why It Matters
If you're using Signal for secure communications, Automatic Key Verification simplifies the process of ensuring message security. It automates the verification of public keys, reducing the risk of key mismatches. However, it may not support chats initiated by searching for a recipient's username, requiring manual verification in such cases.
Comments
Be the first to comment
Enjoyed this article?
Get it daily. 7am. Free. Reads in 5 minutes.
Join 3,478 builders reading daily.