Skip to content
The Nexus
SECURITYAug 11 · 12:04 UTCTHE HACKER NEWS[email protected] (The Hacker News)

Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo

Mozilla has scrapped the cryptographic signing key used for Firefox and Thunderbird downloads on Linux. This action was necessary after an unencrypted copy of the key was mistakenly committed to one of the company's private code repositories. Previously, this key allowed users and Linux distributions to confirm that downloaded Firefox tarballs originated from Mozilla and were untampered with.

Nexus surfaces and summarizes. The full story lives at the source.

Mentioned
Spot something wrong with this article?Report a problem →
Forward this
Related Signal

Adjacent reporting