conv.

All stories
SecurityActive · 21h

Mozilla rotates GPG signing key after accidental GitHub exposure

Mozilla revoked its Firefox and Thunderbird release signing key after an unencrypted copy was inadvertently committed to a private GitHub repository.

Mozilla rotates GPG signing key after accidental GitHub exposure
theregister.com

Conversation activity · last 22 hours peak 7/30m

Peak 7 items in one 30m at Aug 11, 7 AM; 22 items over 22 hours Aug 10, 11:08 PM — no itemsAug 10, 11:38 PM — 2 items · Hacker News 1, Press 1Aug 11, 12:08 AM — no itemsAug 11, 12:38 AM — no itemsAug 11, 1:08 AM — no itemsAug 11, 1:38 AM — no itemsAug 11, 2:08 AM — no itemsAug 11, 2:38 AM — no itemsAug 11, 3:08 AM — 1 item · Lobsters 1Aug 11, 3:38 AM — no itemsAug 11, 4:08 AM — no itemsAug 11, 4:38 AM — no itemsAug 11, 5:08 AM — no itemsAug 11, 5:38 AM — no itemsAug 11, 6:08 AM — no itemsAug 11, 6:38 AM — no itemsAug 11, 7:08 AM — 7 items · Google News 4, Mastodon 2, Press 1Aug 11, 7:38 AM — no itemsAug 11, 8:08 AM — no itemsAug 11, 8:38 AM — no itemsAug 11, 9:08 AM — 5 items · Mastodon 4, Press 1Aug 11, 9:38 AM — 1 item · Mastodon 1Aug 11, 10:08 AM — no itemsAug 11, 10:38 AM — no itemsAug 11, 11:08 AM — 2 items · Hacker News 1, Mastodon 1Aug 11, 11:38 AM — no itemsAug 11, 12:08 PM — 1 item · Mastodon 1Aug 11, 12:38 PM — no itemsAug 11, 1:08 PM — no itemsAug 11, 1:38 PM — 1 item · Mastodon 1Aug 11, 2:08 PM — no itemsAug 11, 2:38 PM — 1 item · Mastodon 1Aug 11, 3:08 PM — no itemsAug 11, 3:38 PM — no itemsAug 11, 4:08 PM — no itemsAug 11, 4:38 PM — no itemsAug 11, 5:08 PM — no itemsAug 11, 5:38 PM — no itemsAug 11, 6:08 PM — no itemsAug 11, 6:38 PM — no itemsAug 11, 7:08 PM — no itemsAug 11, 7:38 PM — no itemsAug 11, 8:08 PM — no itemsAug 11, 8:38 PM — 1 item · Mastodon 1 7 items · 7:08 AM
Aug 114 AM8 AM12 PM4 PMnow · 9:08 PM

Summary, timeline and people extracted by Claude from 22 items across 5 sources · 9h ago. Quotes are verbatim.

Mozilla announced on August 10 that it had moved to a new GPG signing subkey for Firefox and Thunderbird Linux artifacts after discovering an unencrypted copy of the previous subkey was accidentally committed to a private GitHub repository. The company found no evidence the key was accessed by unauthorized parties and revoked the previous key, providing instructions for Linux users to update their package managers accordingly.

  • Mozilla's GPG signing subkey for Firefox and Thunderbird Linux releases was exposed after being accidentally committed unencrypted to a private GitHub repository.
  • Audit logs show no unauthorized access to the exposed key; the repository was restricted to authorized Mozilla personnel.
  • Mozilla revoked the compromised key, deployed a new one (valid through 2028-08-05), and published instructions for Linux users to update their package managers.
  • Different RPM package managers (dnf, zypper) require manual key removal before importing the new signing key to ensure proper verification of future releases.

How it unfolded

  1. Discussion spread across Mastodon with users sharing Mozilla's security blog post and discussing the leaked key exposure and rotation process.

    “Mozilla rotates GPG signing subkey for official Firefox and Thunderbird releases after the previous one leaked (it was inadvertently committed to a private GitHub repository)”

    campuscodi@mastodon.social · Mastodon ↗
  2. The security announcement was posted to Hacker News and other tech platforms, with reporters at BleepingComputer and The Hacker News covering the key rotation incident.

  3. Mozilla discovered an unencrypted copy of its GPG signing subkey for Firefox and Thunderbird Linux artifacts was inadvertently committed to a private GitHub repository. The company revoked the previous signing key and moved to a new subkey.

    “Today, we moved to a new GPG signing subkey used to sign certain Firefox and Thunderbird artifacts (namely Linux tarballs, RPM packages, checksums files) after an unencrypted copy of the previous subkey was inadvertently committed to a…”

    Mozilla · Hacker News ↗
  4. Mozilla's audit review found no evidence that the exposed key was accessed by unauthorized parties. Access to the private repository was limited to Mozilla personnel who already had authorized access to the key through other means.

    “Our review of available audit records found no evidence that the key was accessed by an unauthorized party while it was present in the repository.”

    Mozilla · Hacker News ↗

What people are saying verbatim

“Today, we moved to a new GPG signing subkey used to sign certain Firefox and Thunderbird artifacts (namely Linux tarballs, RPM packages, checksums files) after an unencrypted copy of the previous subkey was inadvertently committed to a private GitHub repository.”

Mozilla, Security team · Mozilla Security Blog ↗ · Aug 9

“Our review of available audit records found no evidence that the key was accessed by an unauthorized party while it was present in the repository.”

Mozilla, Security team · Mozilla Security Blog ↗ · Aug 9

“We have revoked the previous signing key and added safeguards to prevent similar issues in the future.”

Mozilla, Security team · Mozilla Security Blog ↗ · Aug 9

“Enjoy those vibes, nerds.”

cR0w, Mastodon user · Mastodon ↗ · Aug 11, 9:22 AM

“Mozilla rotates GPG signing subkey for official Firefox and Thunderbird releases after the previous one leaked (it was inadvertently committed to a private GitHub repository)”

campuscodi@mastodon.social, Mastodon user · Mastodon ↗ · Aug 11, 7:25 AM

Voices from the web unedited

  • Enjoy those vibes, nerds. https:// blog.mozilla.org/security/2026 /08/10/updated-gpg-key-for-signing-firefox-and-thunderbird-releases/ Today, we moved to a new GPG signing subkey used to sign certain Firefox and Thunderbird artifacts (namely Linux tarballs, RPM packages, checksums files) after an unencrypted copy of the previous subkey was…

    cR0wMastodon · infosec.exchange11h ago24▲view on Mastodon ↗
  • Mozilla rotates GPG signing subkey for official Firefox and Thunderbird releases after the previous one leaked (it was inadvertently committed to a private GitHub repository) https:// blog.mozilla.org/security/2026 /08/10/updated-gpg-key-for-signing-firefox-and-thunderbird-releases/

    campuscodi@mastodon.socialMastodon · infosec.exchange13h ago12▲view on Mastodon ↗
  • What the…??? I mean, leaking a signing key to a private GitHub repository is clearly better than leaking it to a public one. But still, I remember a blog post from something like two decades ago about how Mozilla was using hardware tokens for signing, so that the signing keys could not possibly leak. That probably pre-dated their Linux package…

    WPalantMastodon · infosec.exchange11h ago7▲view on Mastodon ↗
  • 🚨 Mozilla revoked the Firefox and Thunderbird Linux signing key after an unencrypted copy was accidentally committed to a private repo. No unauthorized access was found, but older downloads can stop verifying and some Firefox RPM updates may fail. Read: https:// thehackernews.com/2026/08/mozi lla-revokes-firefox-and-thunderbird.html

    tomcat@infosec.exchangeMastodon · techhub.social9h agoview on Mastodon ↗
  • Mozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub. https://www. bleepingcomputer.com/news/secu rity/mozilla-updates-gpg-key-for-signing-firefox-thunderbird-releases-after-exposure/

    BleepingComputer@infosec.exchangeMastodon · newsie.social11h agoview on Mastodon ↗
  • Bleeping Computer: Mozilla updates GPG signing key for Firefox releases after exposure https://www. bleepingcomputer.com/news/secu rity/mozilla-updates-gpg-key-for-signing-firefox-thunderbird-releases-after-exposure/

    headlines_bot@m.ai6yr.orgMastodon · fosstodon.org11h agoview on Mastodon ↗