Anyone who verifies Firefox and Thunderbird downloads by hand now has extra homework: Mozilla has retired the GPG subkey behind its Linux releases after an unencrypted copy was accidentally committed to a private company repository.
The affected subkey signed Linux tarballs, RPM packages, and checksum files for both products. That key is what lets a user, or a distro bundling the browser, verify that a downloaded archive is genuinely Mozilla’s and untouched. The repository was private, reachable only by a small number of employees who already had authorized access, and a review of audit records turned up no sign of unauthorized access. Mozilla revoked the subkey regardless.
For most users, the swap requires no action. Two sets of users have homework: manual signature checkers must pull in the replacement key plus the old key’s revocation, while anyone installing Firefox from Mozilla’s RPM packages may hit a failed verification.
Signature checkers pay a price: importing the revocation invalidates anything signed with the old key, so previously downloaded files stop verifying too, not just future ones. Reason code 2, “key material has been compromised,” marks the revocation, dated August 6 at 11:14 UTC and annotated “We no longer trust this key.” Mozilla
The replacement subkey went out Monday with fingerprint 827E 6586 0867 9618 CD34 9F93 678E 455D 7676 7AA3, valid through August 5, 2028. Mozilla says it has introduced additional safeguards to prevent a repeat, but did not explain how the unencrypted key ended up in GitHub or how long it sat there.
