TechNewsReel
Live

Mozilla Rotates GPG Signing Keys After Private Repository Leak

The company revoked keys used for Firefox and Thunderbird Linux artifacts after a subkey was accidentally committed to GitHub.

TechNewsReel Newsroom · August 11, 2026

Mozilla has updated the GPG signing subkey used for its Firefox and Thunderbird software artifacts to address a security lapse. The rotation affects Linux tarballs, RPM packages, and checksum files, ensuring the continued integrity of the distribution chain.

The update follows the discovery that an unencrypted copy of the previous signing subkey was inadvertently committed to a private GitHub repository. Upon discovering the leak, Mozilla revoked the compromised key and implemented new safeguards to prevent similar occurrences in the future. According to the Mozilla Security Blog, audit records showed no evidence that the key was accessed by unauthorized parties. The company noted that access to the specific repository was limited to a small group of Mozilla employees who already possessed authorized access to the key.

The Role of GPG Signing

GNU Privacy Guard (GPG) keys are a fundamental security layer for software distributors. By digitally signing releases, Mozilla allows users and system administrators to verify that the software they download is authentic and has not been tampered with by a third party. For high-profile applications like the Firefox browser and Thunderbird email client, these signatures serve as the primary defense against the distribution of modified or malicious binaries.

Implications for Supply-Chain Security

While Mozilla found no evidence of exploitation in this instance, the accidental exposure of a signing key represents a significant security risk. Had an external attacker gained access to the unencrypted subkey, they could have signed malicious versions of Firefox or Thunderbird. Such forged releases would appear as official, legitimate software to both end-users and automated update systems, potentially facilitating a wide-scale supply-chain attack.

Next Steps for Users

Mozilla has already transitioned to the new signing subkey for its Linux artifacts. Users and automated systems that rely on GPG verification for Firefox and Thunderbird updates should ensure they have the updated keys to avoid verification failures. While the risk to current installations is low given the lack of unauthorized access, the incident highlights the ongoing challenge of managing sensitive cryptographic material within development environments.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.