< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-08-11T17:34:51+05:30

Mozilla Revokes Linux Signing Key for Firefox and Thunderbird Over Private Repository Exposure

Mozilla revoked the Linux signing key for Firefox and Thunderbird after an unencrypted copy was mistakenly committed to a private repository, affecting signature verification for older downloads. The revocation highlights risks in cryptographic key management and requires manual updates for some users and distributions.

Mozilla has scrapped the cryptographic key behind Firefox and Thunderbird downloads for Linux after an unencrypted copy of it was committed by mistake to one of the company's own private code repositories.

That key is how a user, or a Linux distribution packaging the browser, confirms a downloaded Firefox tarball came from Mozilla and was not tampered with.

That decision carries a cost for

Read original article

*** END OF TRANSMISSION ***