Mozilla updates GPG signing key for Firefox releases after exposure

Mozilla updates GPG signing key for Firefox releases after exposure
Mozilla updated the GPG key used to sign Firefox and Thunderbird releases after an unencrypted copy was accidentally committed to a private GitHub repository. The company says the risk of supply chain abuse is low, found no evidence of unauthorized access, and has revoked the old key while asking some Linux users and signature-verifying users to update their trust data. #Mozilla #Firefox #Thunderbird #GitHub

Keypoints

  • Mozilla rotated the GPG signing subkey for certain Firefox and Thunderbird artifacts.
  • An unencrypted copy of the old subkey was accidentally committed to a private GitHub repository.
  • Mozilla found no evidence that unauthorized parties accessed the exposed key.
  • The old key was revoked, and measures were added to prevent similar incidents.
  • Some Linux and manual signature-verification users must import the new key and revocation data.

Read More: https://www.bleepingcomputer.com/news/security/mozilla-updates-gpg-key-for-signing-firefox-thunderbird-releases-after-exposure/