we_are_coded.by CODE · The world, decoded
БГ
Mozilla

Mozilla revoked its Firefox signing key after a copy landed in a private repository

Mozilla Security BlogSecurity

The key used to sign Linux packages of Firefox and Thunderbird was revoked on August 10. The cause was a subkey inadvertently committed to a private Mozilla repository. No sign of unauthorised access, and the key was replaced anyway.

In short
  • On August 10 Mozilla revoked the previous signing key for Linux packages of Firefox and Thunderbird.
  • The cause: a copy of the old subkey was inadvertently committed to a PRIVATE Mozilla repository. The company states there is no evidence the key was accessed by an unauthorised party.
  • The new fingerprint is valid until August 2028. Older distributions require manual removal of the old key and import of the new one.
Checked on11 August 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

If your package manager starts shouting tomorrow that a signature cannot be verified, it is not broken. It is planned.

The facts: on August 10 Mozilla revoked the previous signing key for Linux packages of Firefox and Thunderbird. The cause, stated by the company itself: a copy of the old subkey was inadvertently committed to a private Mozilla repository. Mozilla says there is no evidence the key was accessed by an unauthorised party. The new fingerprint is valid until August 2028. Fedora 43 and newer receive the update automatically, with manual fingerprint confirmation; older Fedora, RHEL, Rocky, AlmaLinux and openSUSE require manually removing the old key and importing the new one. There is no CVE number here because there is no software vulnerability - there is an exposed key.

A private repository means closed to outsiders. The risk is low and Mozilla says so plainly. The key was burned regardless, rather than left under observation.

That is the right reflex and it deserves naming. A key that has been somewhere it should not have been gets treated as compromised. No waiting, no probabilities, no explanations about how it probably passed.

A key that ended up in the wrong place is a burned key. Even when nobody took it.

The rule holds for our keys and for yours. Once a secret passes through the wrong channel, it does not get guarded. It gets replaced.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→Mozilla Security Blog - Updated GPG key for signing Firefox and Thunderbird Releases
Original: https://wearecoded.com/en/articles/mozilla-otteglen-klyuch-firefox.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news