Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo

Read full story on The Hacker News
Share
Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo
AI disclosure

Summary

Mozilla has scrapped the cryptographic key behind Firefox and Thunderbird downloads for Linux after an unencrypted copy of it was committed by mistake to one of the company's own private code repositories. That key is how a user, or a Linux distribution packaging the browser, confirms a downloaded Firefox tarball came from Mozilla and was not tampered with. That decision carries a cost for

Original reporting

Open original source

Related coverage

Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.