SECURITY Signal 348
Signal adds Automatic Key Verification to detect man-in-the-middle attacks via a key transparency ledger
Signal introduced Automatic Key Verification, a system using a key transparency ledger and third-party auditors to prevent man-in-the-middle attacks on encrypted chats.
This feature mitigates the risk of a compromised centralized directory redirecting encrypted messages to an attacker by corrupting public keys. Users can enable it by tapping a button in the safety number screen, though the process requires the contact's phone number. The system relies on third-party auditors like Cloudflare and Trail of Bits to verify the ledger's integrity.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
Signal's new Automatic Key Verification feature checks if a contact's public encryption key matches the expected key in a transparency ledger.
The system uses a log tree ledger and prefix tree index, with integrity checks provided by third-party auditors Cloudflare and Trail of Bits.
Users can enable automatic verification via the View Safety Number screen, but the feature requires the contact's phone number.
THE CLUSTER