Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub

https://www.theregister.com/security/2026/08/11/mozilla-revokes-firefox-signing-key-after-unencrypted-copy-lands-in-github/5285908

Audit logs found no unexpected visitors, but release verification still needs an update

64 points · 2 comments · view on lemmy.world

2 Comments

eleijeep@piefed.social · 20 pts · 34d (1 reply)

The Register asked Mozilla how long the private key was sitting in GitHub, how it got there, and whether its audit logs cover the entire period it was exposed, but did not receive a response.

Yeah, I bet I know why.

noodlejetski@piefed.social · 10 pts · 34d

but they prompted it not to make mistakes, how could that happen?!