Summary Mozilla exposed a private GPG signing subkey but found no evidence that an unauthorized party accessed or misused it. Mozilla has admitted that it exposed a private GPG signing subkey in a private GitHub repository, forcing the company to revoke and replace it. However, Mozilla’s mistake demonstrates that even those protections have a weak point: the publisher must keep its private signing key private. Nevertheless, an exposed private signing key could present a serious risk. The first group consists of Linux users who manually verify Mozilla’s GPG signatures for Firefox or Thunderbird downloads.