Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub
Jump to main content
Search
REG AD
SECURITY
Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub
Audit logs found no unexpected visitors, but release verification still needs an update
Carly Page
Carly<br>Page
Published<br>tue 11 Aug 2026 // 12:36 UTC
Mozilla has revoked a cryptographic key used to sign Firefox and Thunderbird releases after discovering someone had accidentally committed an unencrypted copy of the private key to a GitHub repository.<br>The browser maker disclosed the mishap on Monday, saying the GPG private subkey was checked into a private GitHub repository accessible only to a small number of Mozilla employees. All of them were already authorized to access the key through other means.<br>Still, leaving an unencrypted private signing key sitting in source control isn't exactly ideal, so Mozilla revoked the exposed subkey and replaced it.
REG AD
The affected subkey was used to sign Linux tarballs, RPM packages, and checksum files for Firefox and Thunderbird releases. Signing keys allow users and package managers to verify that software really came from Mozilla and hasn't been tampered with along the way.
REG AD
Mozilla said its review of available audit records "found no evidence that the key was accessed by an unauthorized party while it was present in the repository." It has introduced additional safeguards to prevent a repeat, but did not explain how the unencrypted key ended up in GitHub or how long it remained there.<br>For most Firefox and Thunderbird users, the key swap shouldn't require any action. Anyone manually verifying Mozilla's GPG signatures, however, will need to import the new signing key and the revocation for the old one.
MORE CONTEXT
Tech leaders issue letter to train Uncle Sam about value of open weight AI
Firefox 153 contains itself while Thunderbird 153 fixes almost everything
Mozilla speeds Firefox release schedule to biweekly
Dark patterns in Windows are steering users to Edge: Mozilla-commissioned report
The change is a little more involved for users who installed Firefox through Mozilla's RPM repository. On Fedora 43 and later, DNF should download the updated key during the next Firefox update, although users will be asked to approve its import. Mozilla says users running Fedora 42 or earlier, RHEL, Rocky Linux, AlmaLinux, openSUSE, or SUSE will need to remove the old key and manually import its replacement.<br>There's another wrinkle for anyone checking older releases: after importing the revocation, normal signature verification will reject releases signed with the revoked subkey.<br>Thunderbird users don't have to worry about RPM-specific shenanigans, as Mozilla doesn't provide official RPM packages for the email client.<br>The Register asked Mozilla how long the private key was sitting in GitHub, how it got there, and whether its audit logs cover the entire period it was exposed, but did not receive a response. ®
mozilla<br>firefox<br>web browser<br>security
REG AD
security
Feds warn Gunra ransomware is exploiting known bugs to hit critical infrastructure
Newly minted RaaS crew breaks in through using internet-facing kit via known Fortinet flaws, then steals and scrambles data
cyber-crime
Cyberattack on logistics giant CEVA delivers customer data into the wrong hands
Valve, Bol, ING, Ajax, and others affected as pwnage disrupts eight European warehouses
paas and iaas
Why hybrid clouds break and what to do about it
SPONSORED EXPLAINER: There's nothing wrong with hybrid cloud. It's the one-size-fits-all strategy on top of it that's the problem.
Security
Deepfake hiccup unmasks suspected digital certificate fraudster
Face-swap software blinked for 'barely a second,' giving Spanish cops the break they needed
COLUMNISTS
Smart glasses are only smart if we train them to be good. Then they'll be fantastic
Just add smart humans – and a pinch of dog
SECURITY
Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub
Audit logs found no unexpected visitors, but release verification still needs an update
MOST POPULAR
security
Ransomware gangs skip the CEO, head straight for the 40-something IT manager
OS PLATFORMS
Linus Torvalds says AI has made 'huge' Linux kernel updates the new normal
Security
Water system controllers don't belong on the internet, says ex-NSA chief after suspected Iran attacks
networks
‘Humans will be a rounding error on the internet’ says Cloudflare exec
APPLICATIONS
Microsoft tosses Teams Live chat into its feature graveyard
AI
Ai and ML
Anthropic pledges to embed watermarks to help discern AI slop in sop to EU
EU rules cited as reason for effort to trace AI output ancestry
AI and ML
The future is for billionaires – the rest of us will get open weight AI models, maybe
Mark Zuckerberg muses about 'superintelligence' and 'arc of human civilization'
AI AND ML
Zuck rekindles open weights Llama drama with Muse...