One manual check closes the machine-in-the-middle door: compare your safety number with your contact over a channel the network cannot touch. Five minutes, once per contact, and any key substitution between you becomes visible instead of silent. This guide tells you exactly what the number is, why the transparency log cannot replace the check, and how to run it.
Know what the safety number is
Your safety number is a short fingerprint computed from both peers'
ML-DSA-87 identity keys — the keys that sign every
handshake between you. If you and your contact see the same number, you
hold each other's real keys. If an attacker sits between you and
substituted their own keys, the two numbers differ. The mathematics
leaves no third outcome.
Understand why the log is not enough
QERYX logs every identity binding in the Key Transparency System — an append-only Merkle log whose signed tree heads make silent key substitution detectable by auditors and by your own device. The log shrinks the attack to a narrow, expensive window. It cannot shrink the window to zero: transparency detects equivocation after the fact, and detection is not prevention. The out-of-band comparison is the one step that needs your hands, and it is the step that makes the guarantee yours instead of ours.
Run the steps
- Open the conversation with your contact.
- Tap the contact's name, then Verify Safety Number.
-
Compare over a channel the network between you cannot rewrite —
choose one:
- In person: scan each other's QR code. The devices compare for you.
- On a voice or video call: read the number groups aloud, both directions. You are also hearing a voice you know.
- Over another channel you already trust — one you have independently verified.
- Numbers match — mark the contact verified. The verified state persists.
- Numbers differ — stop. Do not send anything sensitive. Re-check on a different channel, and if the mismatch holds, treat the session as intercepted and re-verify after a fresh key exchange.
Act when you see "keys changed"
A key-change notice usually means your contact reinstalled or moved to a new device. It can also mean interception. The residual risk named in the threat model is precisely the user who taps past this prompt: verification after a key change is the entire defense. Re-run §3 before you continue the conversation — especially before anything you would not publish.
References
- Identity and Key Transparency — the log this check completes.
- The QERYX Threat Model §12.2.2 — active machine-in-the-middle at handshake, mitigation and residual risk.
- NIST FIPS 204 — ML-DSA, the identity-signature primitive behind the number.