Cloudflare and Trail of Bits now audit who Signal says you are talking to

Signal’s automatic key verification closes the one gap end-to-end encryption never covered. Encryption proves nobody read your message in transit. It never proved you were sending it to the right person, and for a decade the only fix was comparing codes with a friend in a coffee shop.


Cloudflare and Trail of Bits now audit who Signal says you are talking to
Image Credits Credit: Signal

Here is the problem, and it is easier to state than most people expect. End-to-end encryption scrambles a message so only the recipient can read it.

That works perfectly, provided you were handed the recipient’s real key. The app fetches that key from a server.

If the server hands you a different key, the encryption still functions exactly as designed. It just encrypts your message to somebody else.

The attack that survives perfect encryption

Signal describes the threat plainly. A key gets swapped out without the owner knowing, for example if somebody compromised Signal itself.

Nothing looks wrong at either end. The padlock stays shut, the maths stays sound, and a third party reads everything.

Every encrypted messenger has carried this hole since the beginning. It is why Signal has always shown safety numbers, the long string you were meant to compare with your contact in person or over a separate channel.

Almost nobody did that. A security control that requires a coffee shop is a security control most people skip.

What Signal shipped this week

On Tuesday Signal introduced automatic key verification, in a post by software engineer Katherine Yen. It confirms that the link between a phone number or username and its public key is globally consistent.

Underneath sits a tamper-evident ledger. Signal keeps a log tree and prefix trees recording registrations and account changes, and independent auditors sign each entry.

Your own app checks your identifiers automatically and periodically. Checking a contact still takes a tap on the safety number screen, where the button now returns a green checkmark and the words “Encryption verified”.

Yen made the comparison directly. The checks “provide the same assurance as manually verifying safety numbers”, she wrote, and unlike safety numbers they need no in-person meeting.

Two auditors, not one

This is where the coverage diverges from the sources. Cloudflare announced its role in a release that describes it as one of the external auditors, without naming the other.

Signal names both. Cloudflare and Trail of Bits, the security firm, each sign the ledger independently.

That distinction matters more than it sounds. The entire point of the design is that no single party can show one version of the log to one user and a different version to another.

An audit with one auditor would reintroduce exactly the trust problem it exists to remove.

What the auditor can and cannot see

Cloudflare pulls batches of updates from Signal’s log and checks cryptographically that each update is consistent with everything recorded before it. It then signs the update, and Signal passes the signed version to users.

A user can therefore confirm that Signal is showing them the same log it shows everyone else. From there they check that the log holds the right keys for themselves and their contacts.

The auditor works only over cryptographic proofs. It does not see phone numbers, usernames, public keys or message contents.

Cloudflare built the system in Rust on its own Workers platform, leaning on an append-only verification method from Meta’s open-source key directory library. It has run the same infrastructure for WhatsApp since September 2024, publishing results to a public dashboard.

Meta’s encryption claims have been tested elsewhere. A WhatsApp privacy lawsuit brought after a whistleblower complaint was dismissed.

It is narrower than the word automatic suggests

Signal is unusually candid about the limits, and they are worth reading before anyone calls this solved.

The system does not verify who actually controls a phone number or username. It proves the key belongs to that identifier, not that the identifier belongs to the person you think.

You also need your contact’s phone number. If they use username-only discovery, automatic verification is unavailable.

And if a contact changes their number, the check stops working. Signal tells users to follow up through a secondary, trusted channel, which is the coffee shop again.

The feature can also be switched off. BleepingComputer notes the toggle sits in Settings, under Privacy and then Advanced.

One company now audits both giants

Cloudflare is careful to frame this as a standard rather than a product. Chief technology officer Dane Knecht put it as a progression.

“The web moved to encrypted connections by default with HTTPS,” he said. “Messaging did the same with end-to-end encryption. Independent auditing is the logical next step: not just promising encryption, but making it provable.”

He is right about the direction, and there is a concentration question sitting underneath it. Cloudflare now audits key transparency for both WhatsApp and Signal.

Those are the two largest end-to-end encrypted platforms in the world. A company already carrying a large share of web traffic, and one that decides who may block AI crawlers, is now also a check on private messaging for billions of people.

Trail of Bits is the answer to that objection, and it is a good one. The design survives Cloudflare going bad, which is the whole idea.

Why this lands harder in Europe

A tamper-evident log changes what silence means. Any undisclosed key substitution becomes visible after the fact, to anyone who checks.

That is a live question on this continent. Europe’s telecom chiefs have already pressed for blocking orders against illegal content, and the wider argument about lawful access to encrypted messaging has not gone away.

Signal has been the loudest voice in that room. It has argued at length that AI chatbots are not your friends, and it has treated device-level access as the real threat surface.

The attackers agree. Russian operators tracked as UNC5792 went after Signal accounts through linked devices and recovery keys rather than the encryption itself.

What would settle it

Two things are checkable. The first is whether a third auditor appears, because two is the minimum that makes the argument and it is not obviously enough.

The second is whether anyone else follows. Knecht wants independent auditing to become an expectation rather than an exception, and the honest test is a rival platform adopting it without a press release attached.

For now the useful thing to say is smaller and truer. Encrypted messaging has spent ten years asking users to do a job in a coffee shop, and two of the biggest apps have finally taken it back.

Get the TNW newsletter

Get the most important tech news in your inbox each week.