Mozilla’s investigation will determine how an unencrypted Firefox signing key reached GitHub, whether it was misused, and whether revocation fully contains downstream release risk.
state: resolvedheat: lowuncertainty: lowknownscott: lowsoftware-supply-chain code-signing firefox-securityMozillaFirefox
What is this?
Mozilla disclosed that an unencrypted copy of a previous GPG subkey used to sign Firefox and Thunderbird releases was inadvertently committed to a private GitHub repository. Its review of available audit records found no evidence of unauthorized access; repository access was limited to a small Mozilla group whose members already had authorized access to the key. Mozilla revoked the key and added safeguards against recurrence, stating that most users need take no action, although the supplied snippet does not describe the new controls or the exceptional cases requiring action.
Why it matters to Scott
This is another software-supply-chain key-custody and revocation incident in territory already tracked by radar:concept.software-supply-chain. It directly fits Scott’s cryptographic-trust and defense-in-depth positions, but the supplied evidence neither challenges nor extends them; absent evidence of misuse, incomplete revocation, or novel safeguards, it is primarily another example rather than something that would change what he builds or argues.
ip:concept.cryptographic-trustip:concept.defense-in-depthradar:concept.software-supply-chain
queries asked of Scott's wikis
- code-signing key custody and rotation
- software supply-chain secret leakage controls
- Git repository secret scanning and prevention
- release provenance and artifact verification
- signing-key revocation downstream risk
- incident containment for compromised build credentials
Measured heat
no measured readings yet — the hourly heat pass fills this in
How the heat travelled
no chain yet — the hourly chain pass fills this in
Evidence (2) — ⭐ canonical anchor
Interpretation history
2026-08-11T16:47:56Z
Mozilla’s first-party account establishes an accidental private-repository exposure, reports no unauthorized access, and documents revocation and added safeguards. The latest reobservation adds no substantive evidence, so the bounded incident is best treated as contained unless later misuse or containment failure emerges.
2026-08-11T16:41:57Z
grounded: known/low — This is another software-supply-chain key-custody and revocation incident in territory already tracked by radar:concept.software-supply-chain. It directly fits
2026-08-11T16:39:05Z
origin walked (codex/luna, conf 0.99): anchor hn.story.49259818 -> echo.blog.c8a48a09bd by Mozilla
2026-08-11T16:37:53Z
case created — Exposure and revocation of a browser signing key is a bounded supply-chain incident with potentially material downstream impact.
Decision trace
- 08-12 02:47resolveMozilla’s first-party account establishes an accidental private-repository exposure, reports no unauthorized access, and documents revocation and added safeguards. The latest reobservation adds no sub
- 08-12 02:47alert_silentThe new delta is only a single comment with no additional facts; it does not change the prior assessment of a contained incident and can wait for routine coverage.
- 08-12 02:47alert_routeThe new delta is only a single comment with no additional facts; it does not change the prior assessment of a contained incident and can wait for routine coverage.
- 08-12 02:43alert_silentMozilla confirms the previous Firefox signing subkey was stored unencrypted in a private GitHub repository, but reports no evidence of unauthorized access and has revoked it and added safeguards. With
- 08-12 02:43alert_routeMozilla confirms the previous Firefox signing subkey was stored unencrypted in a private GitHub repository, but reports no evidence of unauthorized access and has revoked it and added safeguards. With
- 08-12 02:41groundThis is another software-supply-chain key-custody and revocation incident in territory already tracked by radar:concept.software-supply-chain. It directly fits Scott’s cryptographic-trust and defense-
- 08-12 02:39promote_anchororigin walk conf 0.99
- 08-12 02:37createExposure and revocation of a browser signing key is a bounded supply-chain incident with potentially material downstream impact.