MOZILLA has rotated the GPG signing key for Firefox and Thunderbird on Linux due to a previously used subkey being unintentionally committed to a private GitHub repository. Although an audit revealed no unauthorized access to the key, Mozilla has not clarified how the subkey was uploaded. Users must take action to replace the old key with the new one for signature verification. Key details include a new fingerprint valid until August 2028. Users verifying manually or via RPM packages need to follow specific steps to ensure proper key import.
Mozilla Rotates Firefox GPG Key After Accidental GitHub Commit
CyberSIXT Evidence Panel
Primary Source
blog.mozilla.org
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
Mozilla Rotates Firefox GPG Key After Accidental GitHub Commit
securityonline.info
-
Mozilla replaces Firefox GPG key after accidental GitHub leak
cybersixt.com