Hacker News
Automatic Key Verification
traceroute66
|next
[-]
Also the ties to phone numbers is not cool in 2026. :(
Dunedan
|previous
[-]
Using a very few selected companies as auditors feels like an odd decision. I'd have rather preferred some kind of web-of-trust like CAcert.org does.
And then there is the final nail in the coffin:
> When Automatic Key Verification is turned on, the Signal client periodically fetches Merkle tree heads from the Signal key transparency server. The client requires that each tree head belong to a lineage endorsed by all registered auditors within the last seven days. If the server does not present valid auditor signatures, the client will raise a warning and Automatic Key Verification will fail. A fully malicious server may therefore maintain a split view of the system for at most one week before client applications start to display warning messages.
(from https://blog.trailofbits.com/2026/08/11/how-trail-of-bits-he...)