Signal Rolls Out Automatic Key Verification to Combat Chat Tampering
Signal has launched an automatic key verification feature to enhance end-to-end encrypted chat security by detecting potential tampering.

Signal has introduced a new security feature designed to automatically verify the integrity of end-to-end encrypted chats, providing users with an additional layer of assurance against tampering. Dubbed "automatic key verification," this feature aims to streamline the process of confirming that conversations have not been intercepted or altered by an unexpected third party.
According to Signal engineer Katherine Yen, the feature offers a "streamlined way to confirm that there’s no unexpected party between you and the other ‘end’ of an end-to-end encrypted session." Unlike manual verification methods, such as comparing safety numbers, these new verifications are performed independently by the user, their Signal connections, and third-party auditors. This process provides the same level of assurance without requiring in-person meetings or secondary communication channels.
The system is built upon the principles of cryptographic key transparency. When a user registers, changes their phone number or username, or recreates their account, these changes are recorded within Signal's key transparency system. This ensures that a specific phone number or username remains consistently associated with a particular encryption key across Signal's network. This consistency guards against scenarios where an attacker might manipulate Signal's key directory to substitute a different encryption key without the account owner's knowledge.
To ensure the integrity and trustworthiness of the key transparency system, Signal has enlisted two independent organizations, Cloudflare and Trail of Bits, to audit the process. Their involvement is crucial for detecting any attempts to present inconsistent versions of key records to different users. Importantly, the information provided to these auditors is cryptographically protected, meaning they do not have access to users' phone numbers or usernames in plaintext, thus preserving user privacy.
While key transparency helps confirm that users are seeing a consistent record of which encryption keys belong to which accounts, it does not verify the real-world identity of the person controlling an account. Furthermore, it does not protect against scenarios where a legitimate account has been completely compromised. The automatic verification feature also currently relies on Signal having the contact's phone number, meaning it may not be available for conversations initiated solely via username. In such cases, users can still resort to manual safety number verification.
Signal frames the risk addressed by this feature as unlikely, requiring either a breach of major cloud infrastructure or a privileged insider targeting a specific account to compromise the key directory. However, the introduction of automatic verification provides a proactive defense against such sophisticated attacks. This move follows recent security enhancements by Signal, including new protections implemented in May after state-sponsored hackers targeted high-profile accounts with fake "Signal Support" alerts.
Users who prefer not to extend trust to Signal and its auditors can disable automatic key verification through the app's Privacy > Advanced settings, allowing them to continue using manual safety number verification exclusively. This flexibility ensures that users can tailor their security preferences to their comfort level.