The key used to sign Linux packages of Firefox and Thunderbird was revoked on August 10. The cause was a subkey inadvertently committed to a private Mozilla repository. No sign of unauthorised access, and the key was replaced anyway.
- On August 10 Mozilla revoked the previous signing key for Linux packages of Firefox and Thunderbird.
- The cause: a copy of the old subkey was inadvertently committed to a PRIVATE Mozilla repository. The company states there is no evidence the key was accessed by an unauthorised party.
- The new fingerprint is valid until August 2028. Older distributions require manual removal of the old key and import of the new one.
If your package manager starts shouting tomorrow that a signature cannot be verified, it is not broken. It is planned.
A private repository means closed to outsiders. The risk is low and Mozilla says so plainly. The key was burned regardless, rather than left under observation.
That is the right reflex and it deserves naming. A key that has been somewhere it should not have been gets treated as compromised. No waiting, no probabilities, no explanations about how it probably passed.
The rule holds for our keys and for yours. Once a secret passes through the wrong channel, it does not get guarded. It gets replaced.