Mozilla Revokes Firefox Signing Key After Security Breach on GitHub
Mozilla has revoked a cryptographic key used to sign Firefox and Thunderbird releases after discovering an unencrypted copy of the private key was accidentally committed to a GitHub repository. The key was accessible only to a small number of Mozilla employees, all of whom were authorized to access it through other means. Despite no evidence of unauthorized access, Mozilla revoked the exposed subkey and replaced it. The affected subkey was used to sign Linux tarballs, RPM packages, and checksum files for Firefox and Thunderbird releases. Mozilla has implemented additional safeguards to prevent similar incidents in the future.