Updated GPG Key for Signing Firefox and Thunderbird Releases

(blog.mozilla.org)

40 points | by csmantle 9 hours ago ago

14 comments

  • noman-land 9 hours ago ago

    If the signing subkey was committed, that implies developers have it as a file on their system which I find surprising if true. They should be using hardware like a Yubikey or something. Especially for something this important.

    • anon7000 9 hours ago ago

      The signing key for Firefox stored on a single hardware yubikey available to a single person?

    • Joel_Mckay 8 hours ago ago

      People don't need an extra supply-chain failure mode to consider, and CVE proved these dongles are mostly security theater. Likewise, the recent Coinkite user key prediction breach certainly wasn't cool for folks that lost their holdings. =3

      • Antirust3743 8 hours ago ago

        Wrong cve and a side channel attack doesn't mean these dongles are useless. It would have stopped the firefox team's ai from commiting their subkey ;)

      • eptcyka 7 hours ago ago

        Storing the secret on a hardware token will most certainly help with not committing into source control.

        • Joel_Mckay 7 hours ago ago

          Most use another build host siloed from the dev staging area, regression tested/audited, and with limited administrative access. =3

          • eptcyka 6 hours ago ago

            Ye, and how do you get source code from devs into that silo?

            • Joel_Mckay 5 hours ago ago

              Usually set up a custom build-bot that pulled a named branch into a VM with a read-only backing image. Had to be done that way for a number of reasons, but mainly simplified dealing with fussy fragile cross-platform build/test environments.

              I should also add even simple visgrep and xdotool can automate a lot of checks that normally takes hours of repetitive testing.

              Best of luck =3

      • perching_aix 6 hours ago ago

        > these dongles are mostly security theater

        ...as opposed to? What's your criteria for "non-security-theater"?

        • Joel_Mckay 6 hours ago ago

          Siloed functional regression test verification, structural audits, and package signing.

          Probably would conclude dev staging areas can't run continuous integration with the current design team. Asking them to take on additional tasks while they already are YOLO'ing it with an LLM is a suckers bet. =3

  • traceroute66 3 hours ago ago

    Isn't this the sort of thing TUF[1] was invented to combat ?

    [1]https://theupdateframework.io/