Security News Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo

Security News
0 Replies 300 Views

Parkinsond

Level 67
Verified
Top Poster
Well-known
Mozilla has scrapped the cryptographic key behind Firefox and Thunderbird downloads for Linux after an unencrypted copy of it was committed by mistake to one of the company's own private code repositories.

That key is how a user, or a Linux distribution packaging the browser, confirms a downloaded Firefox tarball came from Mozilla and was not tampered with.

Most Firefox and Thunderbird users need to do nothing. Two groups do. Anyone who checks signatures by hand must import the new key plus the revocation for the old one. Anyone installing Firefox from Mozilla's RPM packages may hit a failed update and have to swap the key manually.

 
Community
Security tip
Avoid reconnecting everything. After a suspected infection, keep backup drives and shared storage disconnected until you have a recovery plan. Protect the copies you still have.
Back
Top