2026-10-11 17:11 UTC

Mozilla’s investigation will determine how an unencrypted Firefox signing key reached GitHub, whether it was misused, and whether revocation fully contains downstream release risk.

state: resolvedheat: lowuncertainty: lowknownscott: lowsoftware-supply-chain code-signing firefox-securityMozillaFirefox

What is this?

Mozilla disclosed that an unencrypted copy of a previous GPG subkey used to sign Firefox and Thunderbird releases was inadvertently committed to a private GitHub repository. Its review of available audit records found no evidence of unauthorized access; repository access was limited to a small Mozilla group whose members already had authorized access to the key. Mozilla revoked the key and added safeguards against recurrence, stating that most users need take no action, although the supplied snippet does not describe the new controls or the exceptional cases requiring action.

Why it matters to Scott

This is another software-supply-chain key-custody and revocation incident in territory already tracked by radar:concept.software-supply-chain. It directly fits Scott’s cryptographic-trust and defense-in-depth positions, but the supplied evidence neither challenges nor extends them; absent evidence of misuse, incomplete revocation, or novel safeguards, it is primarily another example rather than something that would change what he builds or argues.
ip:concept.cryptographic-trustip:concept.defense-in-depthradar:concept.software-supply-chain
queries asked of Scott's wikis
  • code-signing key custody and rotation
  • software supply-chain secret leakage controls
  • Git repository secret scanning and prevention
  • release provenance and artifact verification
  • signing-key revocation downstream risk
  • incident containment for compromised build credentials

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (2) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnMozilla revokes Firefox signing key after unencrypted copy lands in GitHubconnorboyle20
🟧 echo.blog ⭐Mozilla announced: “an unencrypted copy of the previous subkey was inadvertently committed to a private GitHub repository.” It said audit reMozilla——

Interpretation history

Decision trace