Coming soon The Briev app is almost here. Leave your email and be first in on launch day.

Briev
Live
Technology

Mozilla replaces Firefox signing key after private key was accidentally posted on GitHub

Mozilla withdrew a GPG subkey used for signing Firefox and Thunderbird after an unencrypted copy was mistakenly committed to a private GitHub repo, and issued a replacement key.

Mozilla announced that a private GPG subkey used to sign Firefox and Thunderbird releases was inadvertently committed to a private GitHub repository accessible only to a small group of its staff. Although audit records did not reveal any illicit access, the organization chose to revoke the compromised subkey and publish a replacement. The subkey had been employed to sign Linux tarballs, RPM packages and checksum files, ensuring the integrity of the software.

For the majority of users the key rotation will be transparent, but anyone who manually checks Mozilla's signatures must import the new key and the revocation for the old one. Fedora 43 and later will automatically retrieve the new key during the next update, whereas users on Fedora 42 or earlier, RHEL, Rocky Linux, AlmaLinux, openSUSE and SUSE will need to remove the old key and add the new one manually. Mozilla did not disclose how the key ended up in the repository or how long it remained there, but said additional safeguards have been added.

Why it matters

A compromised signing key could allow tampered Firefox or Thunderbird binaries to appear authentic, so revoking it protects users from potential supply-chain attacks.

In this story

signing keyGPGGitHubFirefoxThunderbirdsupply chainRPM packageskey revocationsoftware verification