Signal introduced Automatic Key Verification, a key transparency mechanism that creates a globally consistent, auditable map of phone numbers to public keys. This mitigates man-in-the-middle attacks where a compromised Signal server substitutes a false public key. Trail of Bits operates one of three independent auditors that sign Merkle tree heads, ensuring clients can verify they see the same key set as all other users. A malicious server can sustain a split view for at most seven days before clients raise warnings.
Signal
1 post
How Trail of Bits helps verify the integrity of your Signal chats