Article may be outdated

This article is 51 days old. Some details may have changed since publication.

Hacker News·4 min read·hard

Updated GPG Key for Signing Firefox and Thunderbird Releases

C
csmantle
✦AI Summary

Mozilla has updated its GPG signing subkey for Firefox and Thunderbird after a previous key was inadvertently exposed in a private repository. Users on certain Linux distributions may need to manually remove the old key to ensure continued update functionality.

Why it matters

This is a critical security maintenance update that ensures the integrity of software updates for millions of users.

✦Dive DeeperCreate a free account to unlock

Today, we moved to a new GPG signing subkey used to sign certain Firefox and Thunderbird artifacts (namely Linux tarballs, RPM packages, checksums files) after an unencrypted copy of the previous subkey was inadvertently committed to a private GitHub repository.

Our review of available audit records found no evidence that the key was accessed by an unauthorized party while it was present in the repository. Access to the repository was limited to a small group within Mozilla, all of whom already had authorized access to the key through other means.

We have revoked the previous signing key and added safeguards to prevent similar issues in the future.

There are two cases where you may need to take action:

Thunderbird does not provide official RPM packages, so there is no RPM-specific action required.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologyscience
✦

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in