LIVE · cybersecurity feed
Live wire
security

Signal adds an extra layer of security to make sure you're actually chatting with the right person

One big caveat, though: You need your contact's phone number

zeroday.news ·

Signal has introduced Automatic Key Verification (AKV), a new security feature designed to prevent man-in-the-middle attacks that could compromise encrypted chats. The feature, announced on Tuesday, August 11, 2026, aims to ensure users are communicating with the intended contact by verifying their public encryption keys.

Signal is widely used by individuals who prioritize privacy, such as diplomats, activists, and journalists. Its existing security measures include end-to-end message encryption and "safety numbers," which are cryptographic fingerprints that users can compare to confirm the integrity of their connection. However, a theoretical vulnerability remained where a malicious actor could tamper with Signal's centralized directory of accounts, impersonating a user and redirecting encrypted messages.

AKV addresses this by establishing a new architecture that detects unauthorized changes to public keys. From a user's perspective, activating AKV is straightforward: users can navigate to a contact's profile, access the "View Safety Number" screen, and tap "Verify automatically." A green checkmark will then indicate that the contact's public encryption key aligns with Signal's key transparency system.

Behind the scenes, Signal has developed an open-source key transparency server that functions as a ledger of public keys. Every modification a user makes to their account information, such as changing a phone number or username, creates a new entry in this ledger. An accompanying index allows users to verify information about themselves or their contacts, ensuring it has not been altered by a third party attempting to intercept messages. Signal's system automatically searches this index on behalf of the user to retrieve the most current information.

To further bolster trust, Signal has engaged third-party auditors, Cloudflare and security firm Trail of Bits. Their role is to verify that Signal's key transparency server itself has not been compromised. These auditors check the index for any signs of tampering and, if clear, sign the response to confirm that the keys provided are consistent for both users, thereby mitigating the risk of a man-in-the-middle attack.

The system also incorporates a monitoring component. Users can interact with the ledger in two ways: by looking up another person's address and by looking up their own. The Signal app periodically and automatically checks a user's own ledger entries. Combined with the ability to manually verify a connection's data via the "Verify Automatically" button, this creates a comprehensive detection system. Auditing ensures that both parties are viewing the same data, while monitoring guarantees regular checks for data accuracy.

A key requirement for using AKV to verify another user is having their phone number linked to their Signal account or present in the user's phone address book. Without this, AKV cannot be used for verification. Users who prefer not to involve a third party in their identity verification have the option to disable AKV and can instead rely on traditional safety number or QR code verification methods.

ShareXLinkedInWhatsAppFacebook

More News

view all →
nation-state

Product showcase: ScamNet looks for warning signs in suspicious calls and shady links

ScamNet: Anti-Scam Suite is a consumer security app from Synaptrex Technologies that helps users detect and block scams involving phone calls, text messages, websites, and other suspicious content. The app is available for iPhone, iPad, and Mac, with features varying by platform. Call protection is available on iPhone, while tools such as Visual Intelligence are supported on iPhone and iPad. The a

vulnerability

Microsoft blames AI for delayed Exchange update, can’t say when it will arrive

Dealing with machine-made bug backlog makes it hard to find a moment to deliver promised subscription service

breach

Chinese AI company Zhipu claims its new is a better bug-finder than Anthropic, OpenAI

PLUS: HCL, TCS, admit data breaches; Google, Apple, India bans some rideshare tips; and more!

breach

SafePal data breach impacts 39,798 customers, stolen info for sale

Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data. [...]

ddos

DDoS Attacks Cause Major Threema Outages

Large DDoS attacks disrupted Threema, causing severe communication outages. Threema On-Prem users were unaffected by the attacks. Threema suffered multiple large-scale DDoS attacks that disrupted its secure messaging service and caused severe communication issues. Organizations using Threema On-Prem were not affected, as their deployments run on their own infrastructure. Threema is a Swiss paid se

security

Anthropic confirms Claude is down in major outage affecting multiple services

Claude is experiencing a major outage, with users reporting login problems and degraded performance across several Anthropic services. [...]