Person
Mozilla
Software vendor — in 1 story, 3 quotes on record.
What they said verbatim
“Today, we moved to a new GPG signing subkey used to sign certain Firefox and Thunderbird artifacts (namely Linux tarballs, RPM packages, checksums files) after an unencrypted copy of the previous subkey was inadvertently committed to a private GitHub repository.”
Mozilla Security Blog · Aug 9 · Mozilla rotates GPG signing key after accidental GitHub exposure
“Our review of available audit records found no evidence that the key was accessed by an unauthorized party while it was present in the repository.”
Mozilla Security Blog · Aug 9 · Mozilla rotates GPG signing key after accidental GitHub exposure
“We have revoked the previous signing key and added safeguards to prevent similar issues in the future.”
Mozilla Security Blog · Aug 9 · Mozilla rotates GPG signing key after accidental GitHub exposure