Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub
tech
The Register reports that Mozilla has revoked a cryptographic signing key used to verify the authenticity of Firefox and Thunderbird releases after an unencrypted copy of the private key was accidentally committed to a GitHub repository. The key was stored in a private repository accessible only to authorized Mozilla employees, and Mozilla's audit logs found no evidence of unauthorized access. Mozilla revoked the compromised key and issued a replacement; most Firefox users won't need to take any action, but anyone manually verifying signatures or running Firefox on Linux will need to import the new key.
Source: https://www.theregister.com/security/2026/08/11/mozilla-r...
Listen to this story
Hear this and more stories in a personalized audio briefing.
Open The Chonkerton