Noticia

Signal adds automatic key verification for safer chats

Signal has introduced automatic key verification, a key-transparency feature designed to make encrypted-chat security checks easier without replacing manual safety numbers.

Imagen editorial de demostración con smartphones en una mesa de pruebas de radio
Las imágenes de demostración se identifican y nunca sustituyen las pruebas del producto.

Signal has introduced automatic key verification, a new security feature designed to make an important encrypted-messaging check easier to complete. In an announcement published on 11 August 2026, the nonprofit messaging service said the feature complements its existing Safety Number system by helping users confirm that a contact’s public encryption key has not been unexpectedly replaced.

Signal’s messages remain end-to-end encrypted. Automatic key verification addresses a different question: whether the key associated with a person’s phone number or username is consistent across Signal’s directory. That distinction matters because encryption can protect a conversation while a compromised directory could theoretically provide the wrong public key for a recipient.

What automatic key verification does

Manual Safety Number verification traditionally requires two people to compare a long number or scan a QR code, often in person or through a separate trusted channel. That remains the strongest direct way to confirm that two users share the same cryptographic identity information, but it is not always practical for everyday contacts.

Automatic key verification uses a broader system of checks performed by the user, their Signal connections and independent third-party auditors. When those checks succeed, Signal displays a green checkmark and the label “Encryption verified” in the contact’s safety-number view. The process is intended to provide the same assurance as manually verifying safety numbers, while removing the need for a meeting or second messaging service in cases where the required information is available.

To try it, open a Signal conversation, visit the contact’s profile, select View Safety Number, then look for the Verify automatically option under Automatic Key Verification. The control appears only when the feature has enough information to perform the check. A successful result is shown inside Signal rather than through a link or code sent by another person.

Key transparency is the foundation

The feature is built on key transparency, a design that records changes to Signal’s directory in a verifiable log. Signal uses that directory to associate public identifiers, such as a phone number or username, with public encryption keys. If an account is registered, recreated or has its phone number or username changed, the event is recorded in the log structure.

Signal compares this system to a public ledger. A user can check their own record, while another person can check the record associated with a connection. The data is organized so that the app can search it efficiently instead of reviewing every historical change. Signal says the public identifiers in the transparency log are cryptographically obscured, using a verifiable random function and a keyed hash so that auditors do not receive the identifiers in plain text.

Independent oversight is another part of the design. Signal identifies Cloudflare and Trail of Bits as trusted third-party auditors. Their role is to check that the same log is presented consistently to different users and that earlier entries are not silently removed or rewritten. This helps detect a malicious attempt to show different versions of the directory to different participants.

The feature has important limits

Automatic key verification does not prove who controls a phone number or username. It confirms the consistency of the public key associated with that identifier, but it cannot establish that the person behind an account is genuinely the person a user believes they are contacting. A user who suspects an account takeover still needs to verify the situation through a separate trusted channel.

There are also practical limits. If a connection was discovered only through a Signal username and the user does not have access to that person’s phone number, automatic verification may not be available. An old phone number can create the same problem: a legitimate number change may look like an unexpected directory difference because the device still holds outdated contact information.

Signal advises treating an unexpected change cautiously. A different key or identifier may have a harmless explanation, but the app cannot distinguish that automatically from interference. In that situation, contact the person through a trusted secondary channel before relying on the earlier verification result.

Manual checks remain available

Users who prefer not to rely on any third party can disable the feature in Settings > Privacy > Advanced > Automatic Key Verification. They can continue using manual Safety Number verification by comparing the displayed number or scanning a QR code with the other person.

That choice is important because automatic key verification is best understood as an additional layer of usability, not a replacement for every security practice. For sensitive conversations, users should still confirm unexpected changes, keep the Signal app updated, protect their phone with a strong screen lock and avoid sharing verification codes or private keys.

A quieter but meaningful security update

Signal’s announcement is technical, but its practical goal is straightforward: make cryptographic consistency checks more accessible to people who use secure messaging without specialist knowledge. The feature does not change the basic promise of end-to-end encryption, and it does not eliminate the need for judgement when an identity or phone number changes.

Its value is that security checks can happen inside the app, using a transparent log and independent auditing instead of relying exclusively on an in-person comparison. For everyday users, that could make it easier to notice unusual changes while preserving manual verification for situations that demand the highest level of confidence.

Fuentes y pruebas

Official source: signal.org (se abre en una pestaña nueva)