Mozilla issued a new GPG signing subkey for some Firefox and Thunderbird artifacts after the previous key was accidentally exposed in a private GitHub repository. The company revoked the exposed key, found no evidence of unauthorized access, and said most users do not need to take action unless they manually verify signatures or use Firefox RPM packages. #Mozilla #Firefox #Thunderbird
Keypoints
- Mozilla replaced a GPG signing subkey after accidental exposure in GitHub.
- The exposed key was used for Firefox and Thunderbird artifacts, including tarballs, RPMs, and checksum files.
- Mozilla found no evidence that an unauthorized party accessed the key.
- The company revoked the old key and issued a new one with added protections.
- Most users do not need action, but manual signature verifiers and Firefox RPM users may need to update keys.
Read More: https://www.securityweek.com/mozilla-issues-new-firefox-gpg-key-following-exposure/