Signal introduced Automatic Key Verification to help users confirm their encrypted chats have not been intercepted, using a key transparency system with Cloudflare and Trail of Bits as independent auditors. The feature complements manual safety number checks and arrives after phishing and social engineering campaigns against Signal users, including attacks linked to Russian state-sponsored hackers, UNC5792, and UNC4221. #Signal #Cloudflare #TrailofBits #UNC5792 #UNC4221
Keypoints
- Signal launched Automatic Key Verification for encrypted chats.
- The feature uses key transparency with Cloudflare and Trail of Bits as auditors.
- It verifies that a phone number or username matches the correct public key.
- Users can enable it in Privacy settings or verify chats manually.
- The update follows phishing attacks against Signal users and related threat groups.