Cybersecurity
Mozilla Revokes Firefox and Thunderbird Signing Key After Exposure
Mozilla has updated its GPG signing key for Firefox and Thunderbird after an unencrypted copy was mistakenly uploaded to GitHub.

Mozilla announced it has revoked the GPG signing key used for releases of Firefox and Thunderbird for Linux. This decision comes after an unencrypted copy of the private subkey was inadvertently committed to one of the company's private code repositories on GitHub.
The key is essential for verifying that downloaded versions of Firefox and Thunderbird have not been tampered with and genuinely come from Mozilla. The exposure of this key poses potential risks to users and Linux distributions packaging the browser.
According to reports, audit logs indicate that there have been no unauthorized access incidents related to the exposure. However, Mozilla emphasized that the release verification process requires an update due to this security flaw.

In light of the incident, some Linux users may need to take action to ensure the integrity of their installations. The update of the signing key aims to maintain trust in the distribution of these software products.
Mozilla has stated there are currently no signs that any unauthorized individuals have accessed the exposed key, as per reports from various sources, including The Register and BleepingComputer.
This incident illustrates the importance of maintaining secure software development practices, especially when managing cryptographic keys that play a critical role in software integrity.