Mozilla’s Major Blunder
This time, Mozilla has really messed up, haven’t they? They’ve had to retract a cryptographic key used for signing Firefox and Thunderbird releases after an unencrypted private key was mistakenly uploaded to GitHub. Oh dear, that’s a huge mistake! The smart folks at Mozilla revealed the details on Monday, stating that the GPG private subkey was committed to a private GitHub repository, which was only accessible to a select few at Mozilla who already had access to the secure keys.
Repository Troubles
You really shouldn’t leave your unencrypted private signing key lying around in source control; that’s a recipe for disaster. Therefore, Mozilla prudently revoked the exposed subkey and replaced it. This incident impacted the keys utilized to sign Linux tarballs, RPM packages, and checksum files for the much-loved Firefox and Thunderbird releases. Signing keys are essential for users to confirm that their software genuinely came from Mozilla and hasn’t been tampered with in transit.
No Indication of Unauthorized Access
Fortunately for Mozilla, their audit logs indicated no suspicious activity involving unauthorized access to the key while it was stored in the repository. They’ve implemented additional security measures to prevent future errors, but they haven’t revealed how the unencrypted key ended up on GitHub or how long it remained there.
Effect on Users
For the majority of Firefox and Thunderbird enthusiasts, this key relocation shouldn’t stir much trouble. However, if you’re among those who manually verify Mozilla’s GPG signatures, you’ll need to import the new signing key and the revocation for the old one. A bit of an inconvenience, isn’t it?
RPM Repository Issues
If you downloaded Firefox from Mozilla’s RPM repository, things become a bit more complicated. For Fedora 43 and beyond, the next Firefox update should handle this by downloading the updated key, although you will need to approve its import. Users sticking with Fedora 42 or earlier, RHEL, Rocky Linux, AlmaLinux, openSUSE, or SUSE will have to remove the old key and manually introduce the replacement. Not perfect, but it’s the situation.
Challenges with Older Releases
For those exploring older releases, there’s another twist: once you’ve imported the revocation, regular signature verification will reject releases signed with the revoked subkey. As for Thunderbird users? No worries! You won’t face any RPM-related issues, as Mozilla doesn’t provide official RPM packages for the email client. A small blessing, right?
Questions for Mozilla
GadgetLad contacted Mozilla with probing inquiries regarding how long the private key was on GitHub, how it ended up there in the first place, and if the logs covered the entire duration it was exposed. Currently, they have remained tight-lipped. We’ll have to wait and see if any answers emerge.
Overview: “Key-Related Chaos”
Mistakes occur, even for top players like Mozilla. They’ve had to pull back a cryptographic key following a mishap with GitHub, replacing it with a new one. Most users can go about their business as usual, but those verifying GPG signatures will have some key management to do. RPM users might face a bit more trouble, but do not worry, Thunderbird users; you’re safe. We’ll relax, enjoy our tea, and await further updates from Mozilla regarding this situation. Stay tuned to gadgetlad.co.uk for more tech news, everyone!