Skip to content
theregister·

🔒Mozilla Revokes Firefox and Thunderbird Signing Key After GitHub Leak

Your Firefox and Thunderbird updates just got a bit more secure

TL;DR

Mozilla revoked a cryptographic key used for Firefox and Thunderbird releases after it was exposed on GitHub. Most users won't need to take action, but manual verifiers will have to import new keys.

Mozilla has revoked a cryptographic signing subkey used to verify the integrity of Firefox and Thunderbird packages due to an accidental exposure in a GitHub repository. This move is crucial for maintaining trust in software distribution channels, especially for those who manually check GPG signatures. The affected key was used to sign Linux tarballs, RPM packages, and checksum files, ensuring that users receive unaltered releases from Mozilla. Most Firefox and Thunderbird users won't need to take action beyond the next automatic update. However, manual verifiers will have to import a new signing key and revoke the old one.

Mozilla Revokes Firefox and Thunderbird Signing Key After GitHub Leak — theregister

Key Points

1

A private subkey used by Mozilla to sign Firefox and Thunderbird releases was accidentally committed to a GitHub repository.

2

The exposure affected Linux tarballs, RPM packages, and checksum files for Firefox and Thunderbird, impacting package verification.

3

Audit records show no unauthorized access during the key's time in the repository, but exact duration is unknown.

4

Most users won't need action; those manually verifying signatures will import new keys and revoke old ones starting now.

5

Fedora 43+ users get updated keys automatically with Firefox updates; others must remove old keys and import replacements.

Why It Matters

If you manually verify Mozilla's GPG signatures, you need to import the new signing key and revoke the old one. This ensures your software remains untampered. The exposure highlights the importance of secure key management practices.

firefoxthunderbirdmozillagpg-signaturesgithub-exposure

Frequently Asked Questions

Why does this matter?

If you manually verify Mozilla's GPG signatures, you need to import the new signing key and revoke the old one. This ensures your software remains untampered. The exposure highlights the importance of secure key management practices.

What happened?

Mozilla revoked a cryptographic key used for Firefox and Thunderbird releases after it was exposed on GitHub. Most users won't need to take action, but manual verifiers will have to import new keys.

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 2,818 builders reading daily.

Also get