Mozilla Withdraws Key Following Discovery of Unencrypted Firefox Signing Key on GitHub
4 hour ago / Read about 0 minute
Author:小编   

Mozilla Corporation recently revoked a private key, utilized for signing the release packages of both the Firefox browser and Thunderbird email client, after inadvertently uploading an unencrypted GPG signing private key to a GitHub repository. As per Mozilla's official statement, this GPG private subkey was accidentally stored in a private GitHub repository. Access to this repository was restricted to a select few Mozilla internal staff members who already possessed legitimate access to the key, but the potential risk prompted the immediate revocation of the key to maintain security standards.

  • C114 Communication Network
  • Communication Home
7 X 24 Track global technological trends
Hot Topic