Mozilla rotates Firefox and Thunderbird signing key after GitHub exposure
Brief
Mozilla has replaced a GPG subkey used to sign some Firefox and Thunderbird releases after an unencrypted copy of the previous key was accidentally committed to a private GitHub repository. The organization says its audit records show no evidence that an unauthorized person accessed the key. Mozilla engineer Ben Hearsum disclosed the incident on August …
The post Mozilla rotates Firefox and Thunderbird signing key after GitHub exposure appeared first on CyberInsider .
