Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub
Audit logs found no unexpected visitors, but release verification still needs an update
Mozilla has revoked a cryptographic key used to sign Firefox and Thunderbird releases following an accidental commit of an unencrypted private key to a GitHub repository. The mishap was disclosed by the company on Monday, revealing that the GPG private subkey was stored in a private GitHub repository accessible only to a few authorized Mozilla employees.
Although the exposed subkey was already authorized for access through alternative means, its presence in source control posed a security risk. Mozilla has revoked the affected subkey, which was used to sign Linux tarballs, RPM packages, and checksum files for Firefox and Thunderbird releases. No evidence of unauthorized access to the key while it was in the repository was found.
Users manually verifying Mozilla's GPG signatures will need to import the new signing key and revocation for the old one. For most users, no action is required. Mozilla has introduced additional safeguards to prevent similar incidents in the future.
Brief written by urgent.news from The Register's own syndicated text. Machine-written — may contain errors; check the original before relying on it.