Signal adds automatic key verification to help prevent Person-in-the-Middle attacks

Signal has added an automatic key verification (AKV) feature to help combat ‘Person-in-the-Middle’ attacks during encrypted chats, the secure messaging platform confirmed this week.

“Signal is always end-to-end encrypted,” Katherine Yen, a software engineer at Signal, said, “and automatic key verification provides an additional, streamlined way to confirm that there’s no unexpected party between you and the other ‘end’ of an end-to-end encrypted session.”

Which is good news for those of us who use the platform because of our jobs or political activism, for example.

Sure, Signal already has a safety number feature. This is a unique code enabling users to verify security with specific contacts, as any change to a verified safety number must be manually approved before a new message is sent. This helps protect against Person-in-the-Middle attacks, as Signal will pop up a notification if a safety number has changed.

However, there are still ways for a determined and skilled attacker to direct your encrypted messages to the wrong destination, no matter how unlikely that might be. This is where the new automatic key verification feature comes in, adopting the Swiss Cheese security model.

Think of slices of cheese with randomly placed holes of differing sizes stacked up; the more you have, the less likely anything will be able to get from one side to the other. AKV adds another slice of cheese into the mix.

Checking Signal’s automatic key verification

To see the feature in action, Yen advised, users can head for a Signal connection’s profile and select View Safety Number | Verify automatically.

“The button will show a green checkmark and ‘Encryption verified’ when the feature is available, and verification succeeds,” Yen explained.

Ah yes, when available. Here comes the rub.

Although AKVs run independently without needing secondary channels or face-to-face meetings, ensuring everyone in the Signal ecosystem sees a transparent, consistent link between a phone number or username and its public encryption key comes with a tradeoff. As the announcement notes: to verify someone else’s key, “you need to have their phone number.”

Yep, connect with someone using the recently added username feature and, assuming you don’t have a phone number as well, AKV does not work. Which is kind of a bummer when privacy is such a, excuse the pun, key thing with certain Signal communications. It seems a shame that you can’t have your security cake and eat it in private.

Industry reaction to Signal AKVs

“Safety numbers have been in Signal for years and hardly anyone ever used them,” said Adam Boynton, Senior Enterprise Strategy Manager at Jamf.

“With automatic key verification, Signal has moved the burden of proof off the user and onto a transparency log checked by independent auditors.”

The privacy issue that I’ve put forward aside, Boynton warns that the AKV feature itself sitting in the privacy settings means “there is still a gap between the feature existing and people actually using it”.

The strongest security controls are the ones you don’t need to enable, and, as Boynton concluded, “ultimately strong encryption fails because the user fails to turn it on”.

More security articles by Davey Winder

About The Author

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.