Mozilla has rotated and revoked an unauthorized GPG key used in Firefox and Thunderbird release artifacts after unencrypted copies of the previous key were mistakenly committed to a private GitHub repository This article explores mozilla release signing. . Despite this finding, Mozilla decided to revoke the old key as a preventive measure and introduced additional safeguards to prevent similar incidents in the future.
Mozilla Revokes Firefox and Thunderbird GPG Signing Key The incident underscores a recurring supply-chain risk: signing infrastructure remains a high-value target due to the potential for an attacker to create legitimate-looking artifacts using compromised release-signing keys, tricking users, package managers, and automated systems into accepting them.
While private repositories mitigate some exposure, they do not entirely eliminate the risk posed by accidentally committed secrets, especially when repository access, audit coverage, backups, clones, or log retention are involved. The new Mozilla release-signing primary key fingerprint is: 14F2 6682 D091 6CDD 81E3 7B6D 61B7 B526 D98F 0353 Its new signing subkey fingerprint is: 827E 6586 0867 9618 CD34 9F93 678E 455D 7676 7AA3 Mozilla stated that the new signing subkey expires on August 5, 2028. Users may encounter issues such as "Import of the key didn’t help, wrong key?"
or "The GPG keys listed for the Mozilla repository are already installed but they are not correct for this package." Signature verification failures can also occur.












