Updated GPG Key for Signing Firefox and Thunderbird Releases

(blog.mozilla.org)

20 points | by csmantle 1 hour ago

1 comments

  • noman-land 1 hour ago
    If the signing subkey was committed, that implies developers have it as a file on their system which I find surprising if true. They should be using hardware like a Yubikey or something. Especially for something this important.
    • Joel_Mckay 5 minutes ago
      People don't need an extra supply-chain failure mode to consider, and CVE-2024-45770 proved these dongles are mostly security theater. Likewise, the recent Coinkite user key prediction breach certainly wasn't cool for folks that lost their holdings. =3
    • anon7000 55 minutes ago
      The signing key for Firefox stored on a single hardware yubikey available to a single person?
      • computerfriend 52 minutes ago
        Multiple hardware devices can have the same key.