Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Private Repository Leak

Mozilla has revoked a cryptographic signing key used to verify Firefox and Thunderbird downloads for Linux. The company took the step after an unencrypted copy of the key was accidentally added to one of its private code repositories.

The signing key plays an important role in software security. Users and Linux distributions can use it to confirm that a downloaded Firefox package came from Mozilla and was not modified by someone else.

Mozilla said there is currently no evidence that an unauthorized person accessed the key. The repository was private, and a review of available audit records found no signs of suspicious access. However, Mozilla decided to revoke the key as a precaution.

Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Private Repository Leak

The revocation means that software signed with the old key will no longer pass verification after users import the revocation information. This affects older Firefox and Thunderbird downloads as well as future releases.

Most Firefox and Thunderbird users will not need to take any action. However, users who manually verify software signatures will need to import Mozilla’s replacement key and the revocation information for the old key.

Users who install Firefox through Mozilla’s RPM packages could also face update problems. Depending on the Linux distribution, the package manager may automatically detect the new key and ask users to confirm its fingerprint. On some systems, however, the update may fail and require the signing key to be replaced manually.

Mozilla published a new signing subkey on August 10. Its fingerprint is 827E 6586 0867 9618 CD34 9F93 678E 455D 7676 7AA3, and it remains valid until August 5, 2028.

The revoked subkey had the fingerprint 09BE ED63 F346 2A2D FFAB 3B87 5ECB 6497 C1A2 0256. It was introduced in April 2025 and was originally expected to remain valid until March 2027. Mozilla therefore revoked it several months earlier than its planned replacement date.

Check Also: This New Malware Targets Chrome, Edge, Firefox, and Bypasses 2FA Security – How to Stay Safe

The revocation certificate lists the reason as “key material has been compromised.” This does not necessarily mean that an attacker obtained the key. Mozilla’s public explanation says the company found the key inside a private repository but has not claimed that anyone outside the company accessed it.

The distinction is important because OpenPGP treats compromised keys differently from normal key rotation. A routine replacement does not automatically invalidate older signatures. A revocation based on possible compromise, however, tells verification software to stop trusting signatures made with the affected key.

The revoked subkey was linked to Mozilla’s primary signing key, which remains valid. Mozilla has used several signing subkeys over the years and normally replaces them roughly every two years. Previous subkeys were retired after reaching their expiry dates. This appears to be the first time Mozilla has revoked one before its scheduled expiration.

See Also: Mozilla Firefox 149 Introduces Free Built-in VPN with 50GB Data

RPM users may need to remove the old key before importing the replacement. Mozilla’s instructions include removing the existing key, importing the new signing key, and clearing the package manager’s cache before trying the update again. Some distributions may handle the process automatically.

The issue does not appear to affect Mozilla’s APT repository used by Debian and Ubuntu users. That repository uses a different signing key, and Debian-based packages are not listed among the affected formats.

Mozilla has not disclosed which private repository contained the key, how long the unencrypted copy remained there, or exactly how the company discovered it. It also has not provided detailed information about the additional security measures introduced after the incident.

For most users, the incident will have little visible impact. However, anyone who manually verifies Firefox or Thunderbird downloads or uses Mozilla’s RPM packages should check the signing key and update it if required.

Mobile Phone Taxes Portal

Find the PTA Taxes on All Phones on a Single Page using our Taxes Portal.

Note: Mobile phone tax rates and calculations fall under the jurisdiction of the Federal Board of Revenue (FBR), not the Pakistan Telecommunication Authority (PTA).

Explore NowFollow us on Google News!

Onsa Mustafa

Onsa is a Software Engineer and a tech blogger who focuses on providing the latest information regarding the innovations happening in the IT world. She likes reading, photography, travelling and exploring nature.

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
>