Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo

Mozilla has scrapped the cryptographic key behind Firefox and Thunderbird downloads for Linux after an unencrypted copy of it was committed by mistake to one of the company’s own private code repositories.

That key is how a user, or a Linux distribution packaging the browser, confirms a downloaded Firefox tarball came from Mozilla and was not tampered with.

That decision carries a cost for

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

GitLost: We Tricked GitHub’s AI Agent into Leaking Private Repos

GitLost: We Tricked GitHub’s AI Agent into Leaking Private Repos Source: Hacker News

Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker

Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker U.S. prosecutors linked an alleged Scattered Spider hacker to a break-in at a luxury jewelry retailer using

The bottleneck might be the air in the room

The bottleneck might be the air in the room Source: Hacker News