August 10, 2026
Key drama hits Firefox
Updated GPG Key for Signing Firefox and Thunderbird Releases
Mozilla swaps Firefox signing key after private repo slip-up, and commenters are asking why this wasn’t locked down harder
TLDR: Mozilla changed the verification key for some Firefox and Thunderbird downloads after the old one was accidentally stored in a private code repo, though it says there’s no evidence anyone misused it. Commenters zeroed in on one spicy question: why was such a sensitive key not locked to special hardware in the first place?
Mozilla dropped a calm-but-serious update on its security blog saying it replaced the digital key used to verify some Firefox and Thunderbird downloads after an unencrypted copy of the old one was accidentally committed to a private GitHub repository. Mozilla says it found no sign of abuse, revoked the old key, and added safeguards. For most people, nothing changes. But Linux users who manually verify downloads, and some people using Firefox packages on older systems, may have to do a little cleanup before updates work again.
The real heat came from the community reaction, which instantly turned this from a dry security note into a mini tech-drama. The strongest opinion was basically: why was such an important secret sitting around as a file at all? One commenter, noman-land, voiced the big trust-shake moment by saying this kind of key should be living on dedicated hardware, not hanging out on a developer machine waiting to become tomorrow’s oopsie. That sparked the classic split-screen internet response: one side treating it as a huge red flag about internal security habits, the other likely to see it as a boring-but-responsible cleanup after an honest mistake.
And yes, there’s dark comedy here too: Mozilla saying “for most users, no action is required” while a chunk of Linux users are reading terminal commands like they’ve just been cast in an emergency reboot sequel. It’s not a disaster, but the comments are serving plenty of ‘this is why we can’t have nice keys’ energy.
Key Points
- •Mozilla rotated the GPG signing subkey for certain Firefox and Thunderbird release artifacts after an unencrypted copy of the previous subkey was accidentally committed to a private GitHub repository.
- •Mozilla said its audit review found no evidence of unauthorized access to the key while it was in the repository, and that repository access was limited to a small internal group already authorized to use the key.
- •The previous signing key has been revoked, and Mozilla said most users do not need to take action unless they manually verify GPG signatures or use Firefox RPM packages on affected distributions.
- •Fedora 43 and later can update the key through dnf during the next update, while Fedora 42 and older, RHEL, Rocky Linux, AlmaLinux, openSUSE, and SUSE-based systems require manual key removal and re-import.
- •Mozilla published the new key fingerprint, the new signing subkey fingerprint, an expiration date of 2028-08-05 for the new subkey, and sources from which users can fetch the new key and revocation.