Theregister
Mozilla Revokes Firefox Signing Key After Unencrypted Exposure on GitHub
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Mozilla has revoked a GPG signing subkey for Firefox and Thunderbird after an unencrypted copy was accidentally committed to a private GitHub repository. The subkey, used for signing Linux tarballs, RPM packages, and checksum files, was accessible only to a limited number of authorized Mozilla employees. An investigation revealed no unauthorized access to the key while it was exposed. Mozilla has implemented additional safeguards but did not disclose how long the key was in the repository or how it was committed. Users of Firefox and Thunderbird are not required to take action, but those manually verifying signatures will need to import the new signing key. RPM users on certain distributions will need to manually update their keys. The incident highlights the risks associated with handling cryptographic keys in source control environments.
Key Points: • Mozilla revoked a GPG signing subkey after it was accidentally exposed on GitHub. • The exposed key was used for signing release files for Firefox and Thunderbird. • No unauthorized access was detected during the key's exposure period.