TECH Signal 198
Signal adds automatic key verification built on key transparency to replace manual safety number checks
Signal introduced automatic key verification, a feature that uses a distributed system of user, connection, and third-party auditor checks to confirm encryption key consistency without requiring in-person meetings or secondary channels.
For engineers building or relying on end-to-end encrypted messaging, this reduces the friction of key verification from a manual out-of-band process to an in-app button tap. The feature guards against a compromised directory swapping keys for targeted accounts, which is a meaningful threat model even if unlikely. Because only one feed carried this story, corroboration is limited.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
Automatic key verification provides the same assurance as manually verifying safety numbers but does not require an in-person meeting or secondary communication channel.
The system relies on verifications performed by the user, their Signal connections, and third-party auditors to ensure the mapping between a phone number or username and its public key is globally consistent.
The feature is accessible via a contact's profile under View Safety Number, where tapping Verify automatically shows a green checkmark and Encryption verified on success.
THE CLUSTER
↗