Mozilla has taken decisive action by revoking a crucial cryptographic key associated with Firefox and Thunderbird Linux downloads. This decision follows the accidental inclusion of an unencrypted version of the key in a private code repository. The key serves as a verification tool ensuring that downloaded Firefox tarballs are authentic and untouched.
Implications for Linux Users
The revocation impacts anyone who verifies downloads, as files signed with the old key will no longer pass checks once the revocation is imported. This affects both older and future downloads of Firefox and Thunderbird. Mozilla assures that the key was not accessed by unauthorized parties, as the repository was private and audit records show no signs of breach. Nevertheless, the company proceeded with the revocation to maintain security integrity.
Actions Required for Specific Users
While most users remain unaffected, specific groups must take action. Users who manually verify signatures need to import the new and revoked keys. Those installing Firefox via RPM packages might experience update failures and require a manual key swap. The newly published subkey, valid until August 2028, comes with the fingerprint 827E 6586 0867 9618 CD34 9F93 678E 455D 7676 7AA3.
Understanding the Revocation
The revocation certificate, decoded by The Hacker News, indicates reason code 2, meaning “key material has been compromised,” with a note stating, “We no longer trust this key.” Although Mozilla’s account does not explicitly confirm key theft, the indicated reason code affects the verification of older downloads. The revoked subkey was initially slated for replacement in March 2027, following Mozilla’s practice of key rotation every two years to preempt undetected leaks.
On the RPM front, some distributions manage the key update automatically, prompting users to confirm the new fingerprint. Others may encounter outright failures, necessitating manual intervention. Users must first remove the old key before importing the new one to prevent errors.
Conclusion and Future Outlook
Mozilla has not disclosed specifics about the repository containing the key or additional safeguards implemented post-incident. The revocation follows a broader context of heightened security in the software supply chain, underscoring the need for vigilance. As Mozilla continues to ensure the security of its software, Linux users are advised to stay informed about any further updates.
