Urgent.News

600+ sources. One page. See who else covered it.

Editions

Business

Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub

Audit logs found no unexpected visitors, but release verification still needs an update

Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub

Mozilla has revoked a cryptographic key used to sign Firefox and Thunderbird releases following an accidental commit of an unencrypted private key to a GitHub repository. The mishap was disclosed by the company on Monday, revealing that the GPG private subkey was stored in a private GitHub repository accessible only to a few authorized Mozilla employees.

Although the exposed subkey was already authorized for access through alternative means, its presence in source control posed a security risk. Mozilla has revoked the affected subkey, which was used to sign Linux tarballs, RPM packages, and checksum files for Firefox and Thunderbird releases. No evidence of unauthorized access to the key while it was in the repository was found.

Users manually verifying Mozilla's GPG signatures will need to import the new signing key and revocation for the old one. For most users, no action is required. Mozilla has introduced additional safeguards to prevent similar incidents in the future.

Brief written by urgent.news from The Register's own syndicated text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Business

More from Tuesday 11 August →