Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub
Jump to main content
Search
REG AD
SECURITY
Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub
Audit logs found no unexpected visitors, but release verification still needs an update
Carly Page
Carly<br>Page
Published<br>tue 11 Aug 2026 // 12:36 UTC
Mozilla has revoked a cryptographic key used to sign Firefox and Thunderbird releases after discovering someone had accidentally committed an unencrypted copy of the private key to a GitHub repository.<br>The browser maker disclosed the mishap on Monday, saying the GPG private subkey was checked into a private GitHub repository accessible only to a small number of Mozilla employees. All of them were already authorized to access the key through other means.<br>Still, leaving an unencrypted private signing key sitting in source control isn't exactly ideal, so Mozilla revoked the exposed subkey and replaced it.
REG AD
The affected subkey was used to sign Linux tarballs, RPM packages, and checksum files for Firefox and Thunderbird releases. Signing keys allow users and package managers to verify that software really came from Mozilla and hasn't been tampered with along the way.
REG AD
Mozilla said its review of available audit records "found no evidence that the key was accessed by an unauthorized party while it was present in the repository." It has introduced additional safeguards to prevent a repeat, but did not explain how the unencrypted key ended up in GitHub or how long it remained there.<br>For most Firefox and Thunderbird users, the key swap shouldn't require any action. Anyone manually verifying Mozilla's GPG signatures, however, will need to import the new signing key and the revocation for the old one.
MORE CONTEXT
Tech leaders issue letter to train Uncle Sam about value of open weight AI
Firefox 153 contains itself while Thunderbird 153 fixes almost everything
Mozilla speeds Firefox release schedule to biweekly
Dark patterns in Windows are steering users to Edge: Mozilla-commissioned report
The change is a little more involved for users who installed Firefox through Mozilla's RPM repository. On Fedora 43 and later, DNF should download the updated key during the next Firefox update, although users will be asked to approve its import. Mozilla says users running Fedora 42 or earlier, RHEL, Rocky Linux, AlmaLinux, openSUSE, or SUSE will need to remove the old key and manually import its replacement.<br>There's another wrinkle for anyone checking older releases: after importing the revocation, normal signature verification will reject releases signed with the revoked subkey.<br>Thunderbird users don't have to worry about RPM-specific shenanigans, as Mozilla doesn't provide official RPM packages for the email client.<br>The Register asked Mozilla how long the private key was sitting in GitHub, how it got there, and whether its audit logs cover the entire period it was exposed, but did not receive a response. ®
mozilla<br>firefox<br>web browser<br>security
REG AD
AI AND ML
Zuck’s Chinese agentic prey escapes, will resume standalone ops
Manus AI will delete some data to satisfy legal requirements
AI AND ML
India’s central bank wants AI to approve loans that humans would reject
Regulator hopes for greater financial inclusion, without extra risk or blaming models for bad decisions
paas and iaas
Why hybrid clouds break and what to do about it
SPONSORED EXPLAINER: There's nothing wrong with hybrid cloud. It's the one-size-fits-all strategy on top of it that's the problem.
AI and ML
Modular's Mojo programming language hits 1.0 milestone
Developers await open source compiler release to dispel uncertainty following Qualcomm acquisition
COLUMNISTS
Smart glasses are only smart if we train them to be good. Then they'll be fantastic
Just add smart humans – and a pinch of dog
security
Signal adds an extra layer of security to make sure you're actually chatting with the right person
One big caveat, though: You need your contact's phone number
MOST POPULAR
security
Ransomware gangs skip the CEO, head straight for the 40-something IT manager
OS PLATFORMS
Linus Torvalds says AI has made 'huge' Linux kernel updates the new normal
Security
Deepfake hiccup unmasks suspected digital certificate fraudster
SECURITY
Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub
ai and ml
Gym rat asks AI agent to book him a class, it hacks a waitlist API to bump him up the list
AI
AI and ML
Modular's Mojo programming language hits 1.0 milestone
Developers await open source compiler release to dispel uncertainty following Qualcomm acquisition
Off-Prem
Together AI embraces the competition with $240M IBM Cloud deal
Deal to fund 'large' deployment of Nvidia's last-gen HGX B300 systems launching in Q1 2027
Ai and ML
Anthropic pledges to embed watermarks to help discern AI slop in sop to EU
EU rules cited as reason for effort to trace AI output...