Mozilla has replaced one of the signing keys used for Firefox and Thunderbird after discovering that an unencrypted copy had been committed to a private GitHub repository.

It sounds worse than it actually is, at least based on what Mozilla has found so far. The repository wasn’t public, and the people who could access it were already authorized to access the key. Still, leaving an unencrypted signing key sitting in source control isn’t exactly something you want to find during a security review.

The key is used to sign some Firefox and Thunderbird downloads, including Linux tarballs, RPM packages and checksum files. Those signatures give users and software a way to check that a file really came from Mozilla and hasn’t been altered somewhere along the way.

That’s why the key itself needs to be protected. Anyone who gets hold of a private signing key could potentially use it to make something malicious appear to have come from the real software publisher.

Mozilla says that’s not what happened here. After reviewing its logs, the company said it “found no evidence that the key was accessed by an unauthorized party while it was present in the repository.”

mozilla-gpg-key-for-signing-firefox-thunderbird-releases-leak

Mozilla has revoked the old key and issued a replacement. It has also made some changes intended to prevent another copy from ending up in a repository.

There’s still one obvious question, though. Mozilla hasn’t said how the key ended up in the GitHub repository or exactly how long it was sitting there. The Register also noted that missing detail in its report, and it’s probably the part security-conscious users will be most interested in.

For most Firefox and Thunderbird users, there’s nothing to do. Mozilla’s normal update process will take care of things without you having to think about the signing key.

Linux users who manually verify Mozilla downloads are the exception. They’ll need to import the replacement GPG key and the revocation for the old one.

There are some extra steps for people using Mozilla’s RPM repository as well. Fedora 43 and newer should handle the change during the next update, although you’ll need to approve the new signing key. Older Fedora versions, as well as RHEL, Rocky, AlmaLinux, openSUSE and SUSE, require the old key to be removed manually before the replacement can be used.

Once the revocation is imported, older packages signed with the retired key will no longer pass verification. That’s expected and doesn’t mean something has suddenly gone wrong with those packages.

Thunderbird users don’t have to worry about the RPM-specific part of this because Mozilla doesn’t provide official RPM packages for Thunderbird.

While all this is going on in the background, Mozilla is also working on user-facing changes to Firefox, the biggest of which is the upcoming Nova redesign that’s already live in the Nightly channel. Apart from that, the company is finding ways to make AI more useful in the browser. Just yesterday we highlighted a new Smart Window feature that lets you use AI to keep track of product prices in the browser. More details on that here.

We stand out from the tech-media crowd because we break news stories; we mainly bring you stuff that you won’t find anywhere in the mainstream tech media. Our stories have been picked up by some of the world’s most popular websites and media outlets—more info is available here.

Dwayne Cubbins
2909 Posts

I cover fast-moving stories across apps, online platforms, and everyday tech — phones, wearables, consoles, and whatever else people are fighting with this week. Bugs, rollouts, scams, policy enforcement, and the occasional internet-culture rabbit hole are all fair game. My goal is simple — make confusing tech news readable. When I'm not working, I'm working out or chilling with my dog. Got a tip? You can find me on X @dcubbins.