HeadlinesBriefing favicon HeadlinesBriefing.com

Mozilla Updates GPG Key for Firefox and Thunderbird Signatures

Hacker News •
×

Mozilla has moved to a new GPG signing subkey for signing Firefox and Thunderbird artifacts, including Linux tarballs, RPM packages, and checksum files. The previous subkey was inadvertently committed to a private Git Hub repository, but an audit found no evidence of unauthorized access. The key was used only by a small group of authorized Mozilla employees.

Mozilla has revoked the old key and added safeguards to prevent similar issues in the future. For most users, no action is required, but those manually verifying signatures or using Firefox RPM packages may need to import the new key and revoke the old one. The new signing key's fingerprint is 827E 6586 0867 9618 CD34 9F93 678E 455D 7676 7AA3 and expires 2028-08-05.