Security
Jump to navigation
Jump to search
Welcome to the Mozilla Security wiki. There is not much here yet so feel free to contribute.
The Team
- Security Severity Ratings
- How to report a security issue
- Want to fix a security bug? Here is a list of old thorny bugs you can take on.
Security reviews for new features/products
Main Article: Security/Reviews
- Find past reviews by Category:SecReview
Security Radar
Unlinked Reviews
- Android System Storage
- WebBattery
- BrowserID C API
- Add crossorigin attribute
- Sync Dialogue
- JetPack 2011-10-12
- XHR non-post rewrite
- Stub Installer
- Sync Client
- Weave 1.3b5 Client
- DNSSEC-TLS
- Web Activities & F1
- MouseLock
- Joystick
Unlinked Discusions
Security Discussions / Possible Features
Security feature work
Main article: Security/Features
Main article: Security/Roadmap
- Content Security Policy proposal and implementation
- Strict Transport Security proposal to prevent network attacks on all-HTTPS sites
- Origin proposal for CSRF and clickjacking mitigation (i.e. anything that requires authentication of the origin of a request)
- Process Isolation: Internal compartmentalization of Firefox architecture
Security Initiatives
- Security:ThePluginProblem
- Security/TeamEmbedding
- Prioritizing and driving non-feature work: Security/Driving
Security Resources and Blogs
Mozilla Official Sites
- Mozilla Security Center
- Mozilla security developer docs
- Mozilla CA Root Program
- Mozilla Security blog
- Mozilla WebApp Sec Blog
- Secure Coding Guidelines for Webapps
Personal Security Related Blogs of Mozillians
- Lucas Adamski's blog
- Sid Stamm's blog
- Curtis Koenig's blog
- Jesse Ruderman's blog (fuzzing entries, security entries)
- Michael Coates
Non-Mozilla Resources (blogs, news sites, twitter, tools)
Stuff that needs to be merged into this page properly
- Security:Strawman Model
- Security:Security Checks In Glue — a possible security model
- Security:Scattered Security Checks — a possible security model
- Security:Wrapper-based Checks — a possible security model
- Security:Bibliography
- Security:EV — summary about EV certification
- File:Intro to Mozilla Metrics.pdf Draft discussion of Security Metrics at Mozilla