Trail of Bits helps Signal verify that your chats aren't being hijacked

How Trail of Bits helps verify the integrity of Signal chats

Trail of Bits helps Signal verify that your chats aren't being hijacked

Signal's Automatic Key Verification uses three independent auditors—Signal, Cloudflare, and Trail of Bits—to ensure the server can't secretly swap your contact's public key. Trail of Bits built its auditor from scratch, continuously signs Merkle tree heads, and commits to a single consistent lineage. If a malicious server tries a split-view attack, clients will warn users within a week. The feature is now available in Signal's privacy settings.

A fully malicious server may therefore maintain a split view of the system for at most one week before client applications start to display warning messages.
  1. pizzaiolo

    Bit of a positive piece amid a negative headline this week: https://cybernews.com/privacy/police-telegram-whatsapp-signa...

  2. chews

    I have worked with Trail of Bits before and their cryptography teams are of the toppest of notches, I still have deep skepticism of Signal though. There are safer ways to use it, never getting push notifications is one part of it. I think their work is admirable, but the need for them to bootstrap you with SMS is a gotcha... they have usernames now, but even with those you have to have to bootstrap it with a number/identity.

More from this day

2026-09-12