Mozilla rotates GPG signing key after accidental GitHub exposure
Mozilla revoked its Firefox and Thunderbird release signing key after an unencrypted copy was inadvertently committed to a private GitHub repository.
Conversation activity · last 22 hours peak 7/30m
Summary, timeline and people extracted by Claude from 22 items across 5 sources · 9h ago. Quotes are verbatim.
Mozilla announced on August 10 that it had moved to a new GPG signing subkey for Firefox and Thunderbird Linux artifacts after discovering an unencrypted copy of the previous subkey was accidentally committed to a private GitHub repository. The company found no evidence the key was accessed by unauthorized parties and revoked the previous key, providing instructions for Linux users to update their package managers accordingly.
- Mozilla's GPG signing subkey for Firefox and Thunderbird Linux releases was exposed after being accidentally committed unencrypted to a private GitHub repository.
- Audit logs show no unauthorized access to the exposed key; the repository was restricted to authorized Mozilla personnel.
- Mozilla revoked the compromised key, deployed a new one (valid through 2028-08-05), and published instructions for Linux users to update their package managers.
- Different RPM package managers (dnf, zypper) require manual key removal before importing the new signing key to ensure proper verification of future releases.
How it unfolded
-
Discussion spread across Mastodon with users sharing Mozilla's security blog post and discussing the leaked key exposure and rotation process.
“Mozilla rotates GPG signing subkey for official Firefox and Thunderbird releases after the previous one leaked (it was inadvertently committed to a private GitHub repository)”
campuscodi@mastodon.social · Mastodon ↗ -
The security announcement was posted to Hacker News and other tech platforms, with reporters at BleepingComputer and The Hacker News covering the key rotation incident.
-
Mozilla discovered an unencrypted copy of its GPG signing subkey for Firefox and Thunderbird Linux artifacts was inadvertently committed to a private GitHub repository. The company revoked the previous signing key and moved to a new subkey.
“Today, we moved to a new GPG signing subkey used to sign certain Firefox and Thunderbird artifacts (namely Linux tarballs, RPM packages, checksums files) after an unencrypted copy of the previous subkey was inadvertently committed to a…”
Mozilla · Hacker News ↗ -
Mozilla's audit review found no evidence that the exposed key was accessed by unauthorized parties. Access to the private repository was limited to Mozilla personnel who already had authorized access to the key through other means.
“Our review of available audit records found no evidence that the key was accessed by an unauthorized party while it was present in the repository.”
Mozilla · Hacker News ↗
What people are saying verbatim
“Today, we moved to a new GPG signing subkey used to sign certain Firefox and Thunderbird artifacts (namely Linux tarballs, RPM packages, checksums files) after an unencrypted copy of the previous subkey was inadvertently committed to a private GitHub repository.”
Mozilla, Security team · Mozilla Security Blog ↗ · Aug 9
“Our review of available audit records found no evidence that the key was accessed by an unauthorized party while it was present in the repository.”
Mozilla, Security team · Mozilla Security Blog ↗ · Aug 9
“We have revoked the previous signing key and added safeguards to prevent similar issues in the future.”
Mozilla, Security team · Mozilla Security Blog ↗ · Aug 9
“Enjoy those vibes, nerds.”
cR0w, Mastodon user · Mastodon ↗ · Aug 11, 9:22 AM
“Mozilla rotates GPG signing subkey for official Firefox and Thunderbird releases after the previous one leaked (it was inadvertently committed to a private GitHub repository)”
campuscodi@mastodon.social, Mastodon user · Mastodon ↗ · Aug 11, 7:25 AM
Voices from the web unedited
-
Enjoy those vibes, nerds. https:// blog.mozilla.org/security/2026 /08/10/updated-gpg-key-for-signing-firefox-and-thunderbird-releases/ Today, we moved to a new GPG signing subkey used to sign certain Firefox and Thunderbird artifacts (namely Linux tarballs, RPM packages, checksums files) after an unencrypted copy of the previous subkey was…
-
Mozilla rotates GPG signing subkey for official Firefox and Thunderbird releases after the previous one leaked (it was inadvertently committed to a private GitHub repository) https:// blog.mozilla.org/security/2026 /08/10/updated-gpg-key-for-signing-firefox-and-thunderbird-releases/
-
What the…??? I mean, leaking a signing key to a private GitHub repository is clearly better than leaking it to a public one. But still, I remember a blog post from something like two decades ago about how Mozilla was using hardware tokens for signing, so that the signing keys could not possibly leak. That probably pre-dated their Linux package…
-
🚨 Mozilla revoked the Firefox and Thunderbird Linux signing key after an unencrypted copy was accidentally committed to a private repo. No unauthorized access was found, but older downloads can stop verifying and some Firefox RPM updates may fail. Read: https:// thehackernews.com/2026/08/mozi lla-revokes-firefox-and-thunderbird.html
-
Mozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub. https://www. bleepingcomputer.com/news/secu rity/mozilla-updates-gpg-key-for-signing-firefox-thunderbird-releases-after-exposure/
-
Bleeping Computer: Mozilla updates GPG signing key for Firefox releases after exposure https://www. bleepingcomputer.com/news/secu rity/mozilla-updates-gpg-key-for-signing-firefox-thunderbird-releases-after-exposure/