3 ms·
Updated GPG Key for Signing Firefox and Thunderbird Releases
- noman-land 2mo agoIf the signing subkey was committed, that implies developers have it as a file on their system which I find surprising if true. They should be using hardware like a Yubikey or something. Especially for something this important.
- anon7000 2mo agoThe signing key for Firefox stored on a single hardware yubikey available to a single person?
- computerfriend 2mo agoMultiple hardware devices can have the same key.
- _bernd 2mo agoYes but then you have to take extra care of this one special system which generates the key on this local system and which transfers the key material to the HSM. Sure it's a valid use case but depending on your requirements this could be a no go. But sharing key files with developers comes also with a price tag.
- pamcake 2mo agoCould be multiple individuals, each with a different key. https://eprint.iacr.org/2020/540 https://eprint.iacr.org/2020/540 https://en.wikipedia.org/wiki/Shamir%27s_Secret_Sharing https://en.wikipedia.org/wiki/Shamir%27s_Secret_Sharing
- kevincox 2mo agoSSS doesn't support signing AFAIK. When I last looked into it GPG/PGP doesn't support shared signing. You can use SSS to encrypt the signing key, but then you need to fully materialize the signing key to actually sign the release. Which makes the exact situation that occurred here possible. The only way to do multi-signer PGP is outside of the PGP protocol, you just need to sign the artifact multiple times then have the verifier assert that a sufficient number of signatures are present. But again, this isn't supported by the regular PGP tools.
- pamcake 2mo agoYou are right that SSS requires temporarily rematerializing the raw key at the moment of signing. Even so it would be a huge improvement: > Which makes the exact situation that occurred here possible. Not so. The situation here was operator errror and someone mistakenly committing signing key in cleartext to repo. So this exact situation would not be possible. They could also have a process of signing on a dedicated instance (possibly with its own shard) which would remove key exposure completely from operator machines. This is all achivable with existing tooling and without changing implementations on verifier side. The first link shows how an actual threshold signature scheme for PGP could be constructed.
- Joel_Mckay 2mo agoPeople don't need an extra supply-chain failure mode to consider, and CVE proved these dongles are mostly security theater. Likewise, the recent Coinkite user key prediction breach certainly wasn't cool for folks that lost their holdings. =3
- Antirust3743 2mo agoWrong cve and a side channel attack doesn't mean these dongles are useless. It would have stopped the firefox team's ai from commiting their subkey ;)
- eptcyka 2mo agoStoring the secret on a hardware token will most certainly help with not committing into source control.
- Joel_Mckay 2mo agoMost use another build host siloed from the dev staging area, regression tested/audited, and with limited administrative access. =3
- eptcyka 2mo agoYe, and how do you get source code from devs into that silo?
- Joel_Mckay 2mo agoUsually set up a custom build-bot that pulled a named branch into a VM with a read-only backing image. Had to be done that way for a number of reasons, but mainly simplified dealing with fussy fragile cross-platform build/test environments. I should also add even simple visgrep and xdotool can automate a lot of checks that normally takes hours of repetitive testing. Best of luck =3
- perching_aix 2mo ago> these dongles are mostly security theater ...as opposed to? What's your criteria for "non-security-theater"?
- ButlerianJihad 2mo agoWhile TFA indicates that "committed" here refers to an inadvertent `git commit`, it is important to note that, in cryptography, there are some very important meanings of "committed key" that are useful and desirable. TFA does not mention these: Key-committing AEAD: https://en.wikipedia.org/wiki/Authenticated_encryption#Key-committing_AEAD https://en.wikipedia.org/wiki/Authenticated_encryption#Key-c... Signing Git commits: https://docs.github.com/en/authentication/managing-commit-signature-verification/signing-commits https://docs.github.com/en/authentication/managing-commit-si...
- traceroute66 2mo agoIsn't this the sort of thing TUF[1] was invented to combat ? [1]https://theupdateframework.io/ https://theupdateframework.io/
- iamnothere 2mo agoI’m surprised that the signing key lives on a non-airgapped system. A sophisticated attacker won’t be leaving any traces.
- angry_octet 2mo agoIt is insane that this key is not kept in a HSM. It would be good if there way a way to attest that a key was generated on and bound to a specific HSM.
- charcircuit 2mo agoAnd this is why Microsoft requires signing keys to live in hardware for signing code.
- skullone 2mo agoEeeesh. Mozilla, wake up to build and signing processes from 20 years ago, please. Don't embarrass yourselves like this.