Mozilla has issued a new GPG signing subkey for certain Firefox and Thunderbird artifacts, including Linux tarballs, RPM packages, and checksum files. This action follows the inadvertent commitment of an unencrypted copy of the previous subkey to a private GitHub repository.
The exposed key was part of a private repository with access limited to a small group within Mozilla, all of whom already had authorized access to the key through other means. A review of available audit records found no evidence that the key was accessed by an unauthorized party while it was present in the repository. Despite this, Mozilla revoked the previous signing key as a precautionary measure.
While a GPG private signing key exposure generally poses a supply chain attack risk, allowing an attacker to sign malicious files that appear authentic, Mozilla assessed the risk as low due to the limited access and lack of unauthorized access evidence.
Most Firefox and Thunderbird users are not required to take any action. However, two specific groups need to act: users who manually verify GPG signatures must import the new signing key and the revocation for the old key. Additionally, users of Firefox RPM packages may need manual intervention, as different RPM package management tools handle GPG key rotations and revocations differently. Thunderbird does not provide official RPM packages, so no RPM-specific action is needed for its users.
Mozilla has implemented new safeguards to prevent similar incidents in the future. The replacement of the key ensures the integrity of future Firefox and Thunderbird releases for Linux users who rely on GPG signature verification.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Mozilla updated the GPG key used to sign Firefox and Thunderbird releases after an unencrypted copy was accidentally committed to a private GitHub repository. The risk of a supply chain attack is considered low, as access to the repository was limited and no unauthorized access to the key has been detected. This update requires manual action for some Linux users and those who verify GPG signatures.
Mozilla revoked the cryptographic key used to sign Firefox and Thunderbird Linux downloads after an unencrypted copy was mistakenly committed to a private code repository. This action means users who manually verify signatures must import a new key and the revocation for the old one, potentially causing failed updates for those installing from Mozilla's RPM packages.
Mozilla has issued a new GPG signing subkey for Firefox and Thunderbird artifacts after the previous key was accidentally exposed in a private GitHub repository. This action mitigates potential supply chain attack risks, even though Mozilla found no evidence of unauthorized access to the exposed key.
Mozilla has replaced the GPG signing subkey used for Firefox and Thunderbird Linux tarballs, RPM packages, and checksum files after an unencrypted copy was inadvertently committed to a private GitHub repository. The previous key has been revoked, and new safeguards are in place, though audit records show no evidence of unauthorized access. This change primarily affects users who manually verify GPG signatures or use Firefox RPM packages on older Linux distributions.