Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub

connorboyle1 pts0 comments

Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub

Jump to main content

Search

REG AD

SECURITY

Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub

Audit logs found no unexpected visitors, but release verification still needs an update

Carly Page

Carly<br>Page

Published<br>tue 11 Aug 2026 // 12:36 UTC

Mozilla has revoked a cryptographic key used to sign Firefox and Thunderbird releases after discovering someone had accidentally committed an unencrypted copy of the private key to a GitHub repository.<br>The browser maker disclosed the mishap on Monday, saying the GPG private subkey was checked into a private GitHub repository accessible only to a small number of Mozilla employees. All of them were already authorized to access the key through other means.<br>Still, leaving an unencrypted private signing key sitting in source control isn't exactly ideal, so Mozilla revoked the exposed subkey and replaced it.

REG AD

The affected subkey was used to sign Linux tarballs, RPM packages, and checksum files for Firefox and Thunderbird releases. Signing keys allow users and package managers to verify that software really came from Mozilla and hasn't been tampered with along the way.

REG AD

Mozilla said its review of available audit records "found no evidence that the key was accessed by an unauthorized party while it was present in the repository." It has introduced additional safeguards to prevent a repeat, but did not explain how the unencrypted key ended up in GitHub or how long it remained there.<br>For most Firefox and Thunderbird users, the key swap shouldn't require any action. Anyone manually verifying Mozilla's GPG signatures, however, will need to import the new signing key and the revocation for the old one.

MORE CONTEXT

Tech leaders issue letter to train Uncle Sam about value of open weight AI

Firefox 153 contains itself while Thunderbird 153 fixes almost everything

Mozilla speeds Firefox release schedule to biweekly

Dark patterns in Windows are steering users to Edge: Mozilla-commissioned report

The change is a little more involved for users who installed Firefox through Mozilla's RPM repository. On Fedora 43 and later, DNF should download the updated key during the next Firefox update, although users will be asked to approve its import. Mozilla says users running Fedora 42 or earlier, RHEL, Rocky Linux, AlmaLinux, openSUSE, or SUSE will need to remove the old key and manually import its replacement.<br>There's another wrinkle for anyone checking older releases: after importing the revocation, normal signature verification will reject releases signed with the revoked subkey.<br>Thunderbird users don't have to worry about RPM-specific shenanigans, as Mozilla doesn't provide official RPM packages for the email client.<br>The Register asked Mozilla how long the private key was sitting in GitHub, how it got there, and whether its audit logs cover the entire period it was exposed, but did not receive a response. ®

mozilla<br>firefox<br>web browser<br>security

REG AD

security

Feds warn Gunra ransomware is exploiting known bugs to hit critical infrastructure

Newly minted RaaS crew breaks in through using internet-facing kit via known Fortinet flaws, then steals and scrambles data

cyber-crime

Cyberattack on logistics giant CEVA delivers customer data into the wrong hands

Valve, Bol, ING, Ajax, and others affected as pwnage disrupts eight European warehouses

paas and iaas

Why hybrid clouds break and what to do about it

SPONSORED EXPLAINER: There's nothing wrong with hybrid cloud. It's the one-size-fits-all strategy on top of it that's the problem.

Security

Deepfake hiccup unmasks suspected digital certificate fraudster

Face-swap software blinked for 'barely a second,' giving Spanish cops the break they needed

COLUMNISTS

Smart glasses are only smart if we train them to be good. Then they'll be fantastic

Just add smart humans – and a pinch of dog

SECURITY

Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub

Audit logs found no unexpected visitors, but release verification still needs an update

MOST POPULAR

security

Ransomware gangs skip the CEO, head straight for the 40-something IT manager

OS PLATFORMS

Linus Torvalds says AI has made 'huge' Linux kernel updates the new normal

Security

Water system controllers don't belong on the internet, says ex-NSA chief after suspected Iran attacks

networks

‘Humans will be a rounding error on the internet’ says Cloudflare exec

APPLICATIONS

Microsoft tosses Teams Live chat into its feature graveyard

AI

Ai and ML

Anthropic pledges to embed watermarks to help discern AI slop in sop to EU

EU rules cited as reason for effort to trace AI output ancestry

AI and ML

The future is for billionaires – the rest of us will get open weight AI models, maybe

Mark Zuckerberg muses about 'superintelligence' and 'arc of human civilization'

AI AND ML

Zuck rekindles open weights Llama drama with Muse...

mozilla firefox github signing after unencrypted

Related Articles