Kryptovaluta-ticker:
sysadmin fra Cyber Security News

Mozilla Revokes Firefox and Thunderbird Signing Key After Unencrypted Subkey Was Committed to GitHub

Abinaya
Tuesday at 14:04
28 Visninger
0 Kommentarer
Mozilla Revokes Firefox and Thunderbird Signing Key After Unencrypted Subkey Was Committed to GitHub

Mozilla has rotated a GPG signing subkey used for selected Firefox and Thunderbird release artifacts after an unencrypted copy of the previous subkey was accidentally committed to a private GitHub repository. The exposed key was used to sign Linux tarballs, RPM packages, and checksum files. Mozilla said the incident did not affect most users, and there is no evidence that an unauthorized party accessed or copied the key. At the same time, it was stored in the repository. The company reviewed available audit logs and found that access to the private GitHub repository was restricted to a small internal Mozilla group. According to Mozilla, every person with repository access was already authorized to access the signing key through...

Les hele artikkelen hos kilden.

Delta i diskusjonen — kommenter, stem og del lenker.

Registrer
Var dette nyttig?
Del:

Kommentarer (0)

Vennligst logg inn eller registrer deg for å delta i diskusjonen

Ingen kommentarer ennå. Bli den første til å kommentere!