Security
Mozilla revokes Firefox signing key after GitHub exposure
Mozilla revoked a Firefox and Thunderbird signing key after an unencrypted copy was accidentally committed to a private GitHub repository.
Mozilla has revoked and replaced a GPG private subkey used to sign Firefox and Thunderbird releases after an unencrypted copy was accidentally committed to a private GitHub repository. The Register reports that the repository was accessible to a small group of Mozilla employees, all of whom were already authorized to access the key through other channels.
The affected key signed Linux tarballs, RPM packages, and checksum files. Mozilla said its audit-log review found “no evidence that the key was accessed by an unauthorized party while it was present in the repository.” The company has added safeguards to prevent a repeat, but has not explained how the key reached GitHub or how long it remained there.
Most users will not need to do anything. People who manually verify Mozilla’s GPG signatures must import the replacement key and the revocation for the old one. Users of Firefox’s RPM repository face additional steps:
- Fedora 43 and later: DNF should download the updated key with the next Firefox update, though users will need to approve the import.
- Fedora 42 and earlier, RHEL, Rocky Linux, AlmaLinux, openSUSE, and SUSE: Users must remove the old key and manually import its replacement.
After the revocation is imported, standard signature verification will reject older releases signed with the revoked subkey. Thunderbird users do not face the RPM-specific issue because Mozilla does not provide official RPM packages for the email client.
Mozilla did not answer The Register’s questions about how the key was exposed, how long it was stored in the repository, or whether the audit logs covered the entire exposure period.