Updated GPG Key for Signing Firefox and Thunderbird Releases (blog.mozilla.org) 56 points by csmantle 1mo ago ↗ HN
[–] noman-land 1mo ago ↗ If the signing subkey was committed, that implies developers have it as a file on their system which I find surprising if true. They should be using hardware like a Yubikey or something. Especially for something this important.
[–] traceroute66 1mo ago ↗ Isn't this the sort of thing TUF[1] was invented to combat ?[1]https://theupdateframework.io/
[–] iamnothere 1mo ago ↗ I’m surprised that the signing key lives on a non-airgapped system. A sophisticated attacker won’t be leaving any traces.
[–] angry_octet 1mo ago ↗ It is insane that this key is not kept in a HSM.It would be good if there way a way to attest that a key was generated on and bound to a specific HSM.
[–] charcircuit 1mo ago ↗ And this is why Microsoft requires signing keys to live in hardware for signing code.
[–] skullone 1mo ago ↗ Eeeesh. Mozilla, wake up to build and signing processes from 20 years ago, please. Don't embarrass yourselves like this.
6 comments
[ 66.3 ms ] story [ 185 ms ] thread[1]https://theupdateframework.io/
It would be good if there way a way to attest that a key was generated on and bound to a specific HSM.