Kryptovaluta-ticker:
sysadmin fra Cyber Security News

Mozilla Revokes Firefox and Thunderbird Signing Key After Unencrypted Subkey Was Committed to GitHub

Abinaya
Tuesday at 14:04
21 Visninger
0 Kommentarer
Mozilla Revokes Firefox and Thunderbird Signing Key After Unencrypted Subkey Was Committed to GitHub

Mozilla has rotated a GPG signing subkey used for selected Firefox and Thunderbird release artifacts after an unencrypted copy of the previous subkey was accidentally committed to a private GitHub repository. The exposed key was used to sign Linux tarballs, RPM packages, and checksum files. Mozilla said the incident did not affect most users, and there is no evidence that an unauthorized party accessed or copied the key. At the same time, it was stored in the repository. The company reviewed available audit logs and found that access to the private GitHub repository was restricted to a small internal Mozilla group. According to Mozilla, every person with repository access was already authorized to access the signing key through...

Læs hele artiklen hos kilden.

Deltag i diskussionen — kommenter, stem og del links.

Registrer
Var dette nyttigt?
Del:

Kommentarer (0)

Log venligst ind eller opret dig for at deltage i diskussionen

Ingen kommentarer ennå. Bli den første til å kommentere!