Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub

11 pointsposted 13 hours ago
by GaryBluto

3 Comments

winstonwinston

7 hours ago

> after an unencrypted copy of the previous subkey was inadvertently committed to a private GitHub repository.

Unencrypted signing key. They just don’t care anymore.

shim__

9 hours ago

Why wasnt that key in an HSM?