Urgent.News

What's breaking now, across thousands of outlets.

Tech

Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub

Audit logs found no unexpected visitors, but release verification still needs an update

Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub

Mozilla has invalidated a key used to verify the authenticity of Firefox and Thunderbird software after a private key was mistakenly uploaded to a GitHub repository. The company disclosed the incident on Monday, explaining that the GPG private subkey was stored in a private GitHub repository accessible only to a limited number of Mozilla employees.

All of these employees already had the necessary authorization to access the key. Despite the existing authorizations, the unencrypted private signing key being in source control was deemed unwise, leading Mozilla to revoke the exposed subkey and issue a replacement. The affected subkey was utilized for signing Linux tarballs, RPM packages, and checksum files for Firefox and Thunderbird releases.

Signing keys enable users and package managers to confirm that software originates from Mozilla and remains unaltered during transit. Mozilla stated that their review of available audit records found no signs of unauthorized access to the key while it was in the repository. Additional measures have been implemented to prevent similar occurrences, but the source of the unencrypted key in GitHub and its duration there remain undisclosed.

For the majority of Firefox and Thunderbird users, the key replacement should not necessitate any action. Those manually verifying Mozilla's GPG signatures will need to import the new signing key and the revocation for the old one. Users installing Firefox via Mozilla's RPM repository will find the change more involved. On Fedora 43 and later, DNF will automatically download the updated key during the subsequent Firefox update, prompting users to approve its import.

Those using Fedora 42 or earlier, RHEL, Rocky Linux, AlmaLinux, openSUSE, or SUSE must remove the old key and manually import the replacement. Users checking older releases should be aware that, after importing the revocation, signature verification of signatures from the revoked subkey will be rejected. Thunderbird users are not affected by the RPM-specific issues, as Mozilla does not provide official RPM packages for the email client.

The Register sought clarification from Mozilla regarding the duration the private key remained in GitHub, how it entered the repository, and whether their audit logs encompass the entire period of exposure. However, no response was provided.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Tech

More from Tuesday 11 August →