Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo

Mozilla revoked the cryptographic signing key for Firefox and Thunderbird Linux downloads after an unencrypted copy was accidentally committed to a private repository, forcing a costly replacement process to maintain download integrity.

Mozilla has revoked the cryptographic signing key for Firefox and Thunderbird Linux downloads after an unencrypted copy was mistakenly committed to one of its private code repositories. The key allowed users and Linux distributions to verify that downloaded tarballs came from Mozilla and were not tampered with. The company stated the decision carries a cost, but did not elaborate on specifics. The breach underscores risks in key management even within private repos.