Signal adds an extra layer of security to make sure you're actually chatting with the right person
One big caveat, though: You need your contact's phone number
Signal, the popular encrypted chat app favored by diplomats, activists, and journalists, has introduced a new feature called Automatic Key Verification (AKV) to bolster its security. This new layer of security aims to prevent man-in-the-middle attacks where someone could potentially intercept messages by corrupting the centralized directory of accounts and posing as another person.
AKV is easy for users to implement. By tapping on a contact’s profile, navigating to the “View Safety Number” screen, and tapping the “Verify automatically” button, users can quickly verify that their contact’s public encryption key matches what Signal's key transparency system expects. If the check passes, a green checkmark will be displayed, confirming the connection remains secure.
Under the hood, Signal has developed a new architecture to detect tampering with public keys associated with an account. This new system acts as a ledger of public keys, with every change a user makes (such as updating their linked phone number) creating a new iteration of the ledger. An accompanying index allows users to verify this information and ensure it hasn't been altered by a malicious third party.
Signal relies on third-party auditors, Cloudflare and Trail of Bits, to verify that its key transparency server itself hasn't been compromised. These auditors check the index to ensure entries haven't been altered. If the checks are clear, the auditors sign a response, confirming the keys provided are the same for both users, thus eliminating the possibility of a man-in-the-middle attack.
While AKV provides an additional layer of security, it still requires users to actively monitor their own ledger entries and verify their connections regularly. This means users must hit the "Verify Automatically" button each time they want to chat with a contact. Additionally, this feature may not be accessible to all Signal users, as verifying another contact's encryption key requires having their phone number through Signal or a matching entry in the user's phone address book.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
