Mozilla employees accidentally placed a private GPG key for Firefox and Thunderbird on GitHub

Mozilla announced the replacement of the GPG key used to sign the release artifacts of Firefox and Thunderbird, such as tar archives, RPM packages, and checksum files. The replacement was made due to an incident in which an unencrypted copy of the key was inadvertently added to the company's private GitHub repository, accessible to a limited number of project participants who had access to the key through internal services.

Audit log analysis found no evidence that third parties accessed the key while it was in the GitHub repository. For most users, replacing the key will not require any action. Exceptions are only for users who manually verify digital signatures or install RPM packages from official Mozilla Firefox builds. In these cases, users will need to explicitly import the new public key and revoke the old one.

For Fedora users up to and including version 42 (in Fedora 43 the key will be replaced automatically) and RHEL/Rocky/Almalinux, execute: sudo rpm -e —allmatches gpg-pubkey-14f26682d0916cdd81e37b6d61b7b526d98f0353 sudo rpm —import https://packages.mozilla.org/rpm/firefox/signing-key.gpg sudo dnf clean all

On openSUSE and SUSE: sudo rpm -e —allmatches gpg-pubkey-14f26682d0916cdd81e37b6d61b7b526d98f0353 sudo rpm —import https://packages.mozilla.org/rpm/firefox/signing-key.gpg sudo zypper refresh

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster