Audit logs found no unexpected visitors, but release verification still needs an update Mozilla has revoked a cryptographic key used to sign Firefox and Thunderbird releases after discovering someone had accidentally committed an unencrypted copy of the private key to a GitHub repository. The browser maker disclosed the mishap on Monday , saying the GPG private subkey was checked into a private GitHub repository accessible only to a small number of Mozilla employees. All of them were already...