Signal has introduced a new security feature called Automatic Key Verification which helps confirm that you are securely connected with your contact using end-to-end encryption. Signal announced the feature in a post sul blog.
Signal messages are always end-to-end encrypted, and Automatic Key Verification provides an additional way to verify your connection. It does not verify the identity of the person behind a Signal account.
Automatic Key Verification is based on key transparency, which helps ensure that Signal devices agree on which encryption keys belong to which account identifiers. While Signal already offers the ability to verify safety numbers between contacts, the process is manual and involves comparing a string of numbers or a QR code with your contact. While the act of verifying safety numbers is an important security practice for sensitive communication, it does require contacts to securely share safety numbers outside of Signal in order to work as intended.
Automatic Key Verification provides an easier solution for confirming end-to-end encryption between you and your contact. Unlike safety numbers, Automatic Key Verification does not require users to manually share safety numbers with each other. Instead, a developer of Signal describes it as “an ongoing system of checks carried out by multiple parties — you, your connection, and independent third-party auditors — each doing their own verification.”
For Signal’s implementation of key transparency, Cloudflare and Trail of Bits serve as trusted third-party auditors. Users who prefer not to rely on any third party can disable the Automatic Key Verification feature in the settings via Privacy > Advanced > Automatic Key Verification and continue to use manual safety number verification.
Automatic Key Verification Availability
The new Automatic Key Verification feature might not be available for all of your contacts. Signal can only perform Automatic Key Verification when it knows your contact’s phone number. For example, you could use Automatic Key Verification with a contact who allows others to find them on Signal via their phone number, but you could not use Automatic Key Verification with a contact that you’ve connected with only via their username. Signal’s support article provides more details about the availability of Automatic Key Verification.
Your messages remain end-to-end encrypted even if Automatic Key Verification is not available.
How to use Automatic Key Verification in Signal
Automatic Key Verification is available in the latest versions of Signal for Android, iOS and Desktop.
To use Key Verification for a contact, navigate to their profile and then select “View safety number”. This will bring you to the safety number screen where you can tap “Verify automatically” under the “Automatic Key Verification” title if the feature is available.
For those interested in the technical details, the Key Transparency Server repository is available on GitHub.
Resta informato
Vuoi rimanere aggiornato sulle ultime novità Signal notizie, suggerimenti e aggiornamenti? Seguici su Threads, Bluesky o Mastodon.





