Mozilla Revokes Firefox Signing Key After Unencrypted Subkey Was Committed to GitHub

Mozilla has rotated a GPG signing subkey used for selected Firefox and Thunderbird release artifacts after an unencrypted copy of the previous subkey was accidentally committed to a private GitHub repository. The exposed key was used to sign Linux tarballs, RPM packages, and checksum files. Mozilla said the incident did not affect most users, and […]

This article has been indexed from Cyber Security News

Read the original article: