Back to all lessons
Awareness Lessons
2 months ago

Mozilla's Signing Key Accidentally Committed to Code Repo

A cryptographic signing key for Firefox and Thunderbird Linux packages was inadvertently committed in unencrypted form to a private repository, violating the fundamental principle that private keys must never be stored in version control systems. Although the repository was private and no external compromise is suspected, the mere exposure of an unencrypted key to an unintended location necessitated full revocation to maintain the integrity of the trust chain. This incident highlights how accidental insider mistakes — not just malicious attacks — can undermine cryptographic infrastructure. The downstream impact on users who rely on signature verification underscores how key mismanagement creates real-world disruption even without a confirmed breach.

Tactical Insight

Immediate actions

  • Audit all code repositories (public and private) for accidentally committed secrets, keys, or credentials using secret-scanning tools.
  • Rotate and revoke any cryptographic keys or credentials found in version control, regardless of repository visibility.
  • Notify affected users and downstream package consumers promptly when a key revocation impacts verification workflows.

Long-term improvements

  • Enforce pre-commit hooks and CI/CD pipeline secret-scanning (e.g., GitGuardian, truffleHog) to block accidental key or credential commits before they land in any repository.
  • Store all private signing keys in dedicated secrets management systems (e.g., HashiCorp Vault, AWS KMS) with strict access controls and never allow keys to exist as plaintext files in developer workspaces.
  • Implement a formal key management policy that defines key lifecycle, storage requirements, and mandatory encryption-at-rest for all cryptographic material.

Detection measures

  • Configure continuous monitoring on repositories to alert on file patterns matching private keys or high-entropy strings.
  • Maintain an inventory of all active signing keys with ownership, expiry, and storage location documented and reviewed quarterly.