Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Signal Introduces Automatic Key Verification (AKV) to Enhance Security Features


Signal has introduced Automatic Key Verification (AKV), a new feature designed to enhance the security of its encrypted messaging app by preventing the "man-in-the-middle" attack. The system involves a ledger of public keys, an index, and regular monitoring to ensure that users can verify their connection's data is correct.

  • Signal introduces Automatic Key Verification (AKV) to enhance security features
  • AKV prevents "man-in-the-middle" attacks by detecting tampered public keys
  • A ledger of public keys is created and updated with user changes, with an index for searching and verification
  • Third-party auditors verify the integrity of the index and key transparency server
  • Users can monitor their ledger entries and compare contact's public encryption keys for added security
  • AKV still relies on user effort, requiring frequent verification to ensure contact identity



  • Signal, a popular encrypted messaging app favored by diplomats, activists, and journalists, has taken significant strides in enhancing its security features with the introduction of Automatic Key Verification (AKV). This innovative system aims to prevent the notorious "man-in-the-middle" attack, where an attacker intercepts messages by corrupting the centralized directory of accounts. By implementing AKV, Signal is bolstering its commitment to providing a secure communication platform for its users.

    To combat this security threat, Signal has developed a new architecture that detects whether someone has tampered with public keys associated with an account. This system involves the creation of a ledger of public keys, which is updated every time a user makes changes to their information, such as updating their phone number or username. An index is also created to facilitate searching through this log tree, allowing Signal users to verify their connection's data is correct.

    Behind the scenes, Signal has partnered with third-party auditors, including Cloudflare and security firm Trail of Bits, to verify that the index and key transparency server are not compromised. These auditors perform regular checks on the index to ensure entries have not been altered and sign the response to confirm that the keys being provided are the same for both users.

    The new system also includes a monitoring feature, where users can regularly check their own ledger entries via the Signal app to verify their connection's data is correct. Additionally, users can compare their contact's public encryption key with what Signal's key transparency system expects, which provides an extra layer of security.

    However, it is worth noting that AKV still leaves Signal users on the hook for their security. If a user wants to be truly sure their contact is who they say they are, they will need to hit the "Verify Automatically" button every time they want to chat. Furthermore, if a user does not have their contact's phone number through Signal or a matching entry in their phone's address book, they cannot use AKV to verify the encryption key associated with that contact.

    In conclusion, Signal's introduction of Automatic Key Verification (AKV) represents a significant step forward in enhancing the security features of its encrypted messaging platform. By implementing this system, Signal is better equipped to prevent the "man-in-the-middle" attack and provide users with an additional layer of protection for their communications.

    Related Information:
  • https://www.ethicalhackingnews.com/articles/Signal-Introduces-Automatic-Key-Verification-AKV-to-Enhance-Security-Features-ehn.shtml

  • https://www.theregister.com/security/2026/08/11/signal-adds-an-extra-layer-of-security-to-make-sure-youre-actually-chatting-with-the-right-person/5286461


  • Published: Tue Aug 11 17:38:51 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us