2026-08-11 14:04 UTC
What the…??? I mean, leaking a signing key to a private GitHub repository is clearly better than leaking it to a public one. But still, I remember a blog post from something like two decades ago about how Mozilla was using hardware tokens for signing, so that the signing keys could not possibly leak. That probably pre-dated their Linux package repositories, so either the concept wasn’t used consistently after that or at some point performance became more important than protecting key material (Mozilla’s infrastructure is producing lots of builds).
https://blog.mozilla.org/security/2026/08/10/updated-gpg-key-for-signing-firefox-and-thunderbird-releases/
Replies (0)
No replies.