← All stories
● Covered by 4 sources · 4 reportsMedium impact1 negative3 neutral

Mozilla Replaces GPG Signing Key for Firefox and Thunderbird After Accidental Exposure

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Mozilla replaced a GPG signing subkey for Firefox/Thunderbird.
  • The old key was accidentally committed to a private GitHub repository.
  • No evidence of unauthorized access was found.
  • The old key has been revoked; new safeguards are in place.
  • Manual action is required for some Linux users and GPG verifiers.

Key Replacement Initiated

Mozilla has issued a new GPG signing subkey for certain Firefox and Thunderbird artifacts, including Linux tarballs, RPM packages, and checksum files. This action follows the inadvertent commitment of an unencrypted copy of the previous subkey to a private GitHub repository.

Exposure and Risk Assessment

The exposed key was part of a private repository with access limited to a small group within Mozilla, all of whom already had authorized access to the key through other means. A review of available audit records found no evidence that the key was accessed by an unauthorized party while it was present in the repository. Despite this, Mozilla revoked the previous signing key as a precautionary measure.

While a GPG private signing key exposure generally poses a supply chain attack risk, allowing an attacker to sign malicious files that appear authentic, Mozilla assessed the risk as low due to the limited access and lack of unauthorized access evidence.

User Impact and Required Actions

Most Firefox and Thunderbird users are not required to take any action. However, two specific groups need to act: users who manually verify GPG signatures must import the new signing key and the revocation for the old key. Additionally, users of Firefox RPM packages may need manual intervention, as different RPM package management tools handle GPG key rotations and revocations differently. Thunderbird does not provide official RPM packages, so no RPM-specific action is needed for its users.

Preventative Measures

Mozilla has implemented new safeguards to prevent similar incidents in the future. The replacement of the key ensures the integrity of future Firefox and Thunderbird releases for Linux users who rely on GPG signature verification.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Mozilla updated the GPG key used to sign Firefox and Thunderbird releases after an unencrypted copy was accidentally committed to a private GitHub repository. The risk of a supply chain attack is considered low, as access to the repository was limited and no unauthorized access to the key has been detected. This update requires manual action for some Linux users and those who verify GPG signatures.

Mozilla revoked the cryptographic key used to sign Firefox and Thunderbird Linux downloads after an unencrypted copy was mistakenly committed to a private code repository. This action means users who manually verify signatures must import a new key and the revocation for the old one, potentially causing failed updates for those installing from Mozilla's RPM packages.

Mozilla has issued a new GPG signing subkey for Firefox and Thunderbird artifacts after the previous key was accidentally exposed in a private GitHub repository. This action mitigates potential supply chain attack risks, even though Mozilla found no evidence of unauthorized access to the exposed key.

Mozilla has replaced the GPG signing subkey used for Firefox and Thunderbird Linux tarballs, RPM packages, and checksum files after an unencrypted copy was inadvertently committed to a private GitHub repository. The previous key has been revoked, and new safeguards are in place, though audit records show no evidence of unauthorized access. This change primarily affects users who manually verify GPG signatures or use Firefox RPM packages on older Linux distributions.