Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub

GaryBluto1 pts0 comments

Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub

Jump to main content

Search

REG AD

SECURITY

Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub

Audit logs found no unexpected visitors, but release verification still needs an update

Carly Page

Carly<br>Page

Published<br>tue 11 Aug 2026 // 12:36 UTC

Mozilla has revoked a cryptographic key used to sign Firefox and Thunderbird releases after discovering someone had accidentally committed an unencrypted copy of the private key to a GitHub repository.<br>The browser maker disclosed the mishap on Monday, saying the GPG private subkey was checked into a private GitHub repository accessible only to a small number of Mozilla employees. All of them were already authorized to access the key through other means.<br>Still, leaving an unencrypted private signing key sitting in source control isn't exactly ideal, so Mozilla revoked the exposed subkey and replaced it.

REG AD

The affected subkey was used to sign Linux tarballs, RPM packages, and checksum files for Firefox and Thunderbird releases. Signing keys allow users and package managers to verify that software really came from Mozilla and hasn't been tampered with along the way.

REG AD

Mozilla said its review of available audit records "found no evidence that the key was accessed by an unauthorized party while it was present in the repository." It has introduced additional safeguards to prevent a repeat, but did not explain how the unencrypted key ended up in GitHub or how long it remained there.<br>For most Firefox and Thunderbird users, the key swap shouldn't require any action. Anyone manually verifying Mozilla's GPG signatures, however, will need to import the new signing key and the revocation for the old one.

MORE CONTEXT

Tech leaders issue letter to train Uncle Sam about value of open weight AI

Firefox 153 contains itself while Thunderbird 153 fixes almost everything

Mozilla speeds Firefox release schedule to biweekly

Dark patterns in Windows are steering users to Edge: Mozilla-commissioned report

The change is a little more involved for users who installed Firefox through Mozilla's RPM repository. On Fedora 43 and later, DNF should download the updated key during the next Firefox update, although users will be asked to approve its import. Mozilla says users running Fedora 42 or earlier, RHEL, Rocky Linux, AlmaLinux, openSUSE, or SUSE will need to remove the old key and manually import its replacement.<br>There's another wrinkle for anyone checking older releases: after importing the revocation, normal signature verification will reject releases signed with the revoked subkey.<br>Thunderbird users don't have to worry about RPM-specific shenanigans, as Mozilla doesn't provide official RPM packages for the email client.<br>The Register asked Mozilla how long the private key was sitting in GitHub, how it got there, and whether its audit logs cover the entire period it was exposed, but did not receive a response. ®

mozilla<br>firefox<br>web browser<br>security

REG AD

AI AND ML

Zuck’s Chinese agentic prey escapes, will resume standalone ops

Manus AI will delete some data to satisfy legal requirements

AI AND ML

India’s central bank wants AI to approve loans that humans would reject

Regulator hopes for greater financial inclusion, without extra risk or blaming models for bad decisions

paas and iaas

Why hybrid clouds break and what to do about it

SPONSORED EXPLAINER: There's nothing wrong with hybrid cloud. It's the one-size-fits-all strategy on top of it that's the problem.

AI and ML

Modular's Mojo programming language hits 1.0 milestone

Developers await open source compiler release to dispel uncertainty following Qualcomm acquisition

COLUMNISTS

Smart glasses are only smart if we train them to be good. Then they'll be fantastic

Just add smart humans – and a pinch of dog

security

Signal adds an extra layer of security to make sure you're actually chatting with the right person

One big caveat, though: You need your contact's phone number

MOST POPULAR

security

Ransomware gangs skip the CEO, head straight for the 40-something IT manager

OS PLATFORMS

Linus Torvalds says AI has made 'huge' Linux kernel updates the new normal

Security

Deepfake hiccup unmasks suspected digital certificate fraudster

SECURITY

Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub

ai and ml

Gym rat asks AI agent to book him a class, it hacks a waitlist API to bump him up the list

AI

AI and ML

Modular's Mojo programming language hits 1.0 milestone

Developers await open source compiler release to dispel uncertainty following Qualcomm acquisition

Off-Prem

Together AI embraces the competition with $240M IBM Cloud deal

Deal to fund 'large' deployment of Nvidia's last-gen HGX B300 systems launching in Q1 2027

Ai and ML

Anthropic pledges to embed watermarks to help discern AI slop in sop to EU

EU rules cited as reason for effort to trace AI output...

mozilla firefox github signing unencrypted security

Related Articles