SECURITYTHE HACKER NEWS
Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo
Mozilla has scrapped the cryptographic signing key used for Firefox and Thunderbird downloads on Linux. This action was necessary after an unencrypted copy of the key was mistakenly committed to one of the company's private code repositories. Previously, this key allowed users and Linux distributions to confirm that downloaded Firefox tarballs originated from Mozilla and were untampered with.
Mentioned
Related Signal
Adjacent reporting
- Mozilla boasts Mythos boosted Firefox bug cull
- Firefox 153 contains itself while Thunderbird 153 fixes almost everything
- Microsoft shuts down illegal code-signing operation used by ransomware crims to mask their malware
- Mozilla says it patched 271 Firefox vulnerabilities thanks to Anthropic's Claude Mythos
- Why a 2017 Linux bug is now a major concern for the crypto industry
- Mozilla Thunderbolt