Toggle light / dark theme

Mozilla updates GPG signing key for Firefox releases after exposure

Mozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub.

However, in a Monday blog post, it noted that the risk of a supply chain attack in which threat actors could distribute malicious installers signed with the exposed key is low because only a limited number of individuals had access to the GitHub repository.

Additionally, Mozilla has yet to find evidence that the previous GPG key was accessed by unauthorized parties while being exposed.

Leave a Comment

Lifeboat Foundation respects your privacy! Your email address will not be published.

/* */