The Chonkerton

Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub

tech

The Register reports that Mozilla has revoked a cryptographic signing key used to verify the authenticity of Firefox and Thunderbird releases after an unencrypted copy of the private key was accidentally committed to a GitHub repository. The key was stored in a private repository accessible only to authorized Mozilla employees, and Mozilla's audit logs found no evidence of unauthorized access. Mozilla revoked the compromised key and issued a replacement; most Firefox users won't need to take any action, but anyone manually verifying signatures or running Firefox on Linux will need to import the new key.

Source: https://www.theregister.com/security/2026/08/11/mozilla-r...

Listen to this story

Hear this and more stories in a personalized audio briefing.

Open The Chonkerton