Mozilla replaces Firefox and Thunderbird GPG key after accidental exposure

 

Mozilla replaces Firefox and Thunderbird GPG key after accidental exposure

Mozilla has updated the GPG signing key used for some Firefox and Thunderbird releases after an unencrypted copy of the previous key was accidentally committed to a private GitHub repository.

Mozilla said the risk of a supply chain attack is low because access to the repository was limited to a small group of employees. The company also said it found no evidence that an unauthorized person accessed the exposed key.

After discovering the issue, Mozilla revoked the old key and moved to a new signing subkey. The change affects Linux tarballs, RPM packages, and checksum files for Firefox and Thunderbird.

Most users do not need to take any action. However, users who manually verify GPG signatures must import the new signing key and the revocation for the old one. Linux users who install Firefox through RPM packages may also need to update their systems manually, depending on their distribution.

Thunderbird users do not need to make RPM-specific changes because Thunderbird does not provide official RPM packages.

The new signing subkey is set to expire on August 5, 2028. Mozilla has also introduced additional measures to prevent similar key exposure incidents in the future.


Back to the list