“Individuals’ security and privacy on the Internet are fundamental and must not be treated as optional.” - Mozilla Manifesto Principle 4
The Mozilla Security community provides leadership in security by building security features, testing software and systems, and leading industry standards to ensure that individuals retain the ability to make meaningful choices about security and privacy on the Internet.
This page documents the security-related activities where Mozilla active, and how to join us.
- 1 Reporting Security Issues
- 2 Security at Mozilla
- 3 Information for developers
- 4 Contributing to the security of Mozilla products
- 5 Mozilla Official Sites
Reporting Security Issues
Mozilla relies on the security community to help secure our products and websites by reporting security issues. Our preference is to receive bug reports via our bug tracking system Bugzilla, however emailing firstname.lastname@example.org (preferably encrypted) is also an option.
Details on the way we classify security bugs can be found here.
Security at Mozilla
Who are we?
Security at Mozilla is distributed among the following teams:
- Security Engineering: Development of Firefox & underlying platform security features.
- Enterprise Information Security: Defines and operates security controls across the organization.
- Cloud Services Security: Securing core Firefox services.
The Mozilla security team is available via a number of channels:
- Via email
- email@example.com: to contact us privately or reporting security bugs
- firstname.lastname@example.org: this is the best place to ask security questions that don't need to be private. You might also try searching this list for answers to your questions
- You can also find us on a number of security related mailing lists including W3C WebAppSec
- Via Mozilla IRC
- #security - general security discussions
- #contentsecurity - browser security engineering, DOM, CSP, Origins, content blocking etc
- #infosec - general infosec discussions
- Join our security/meetings public meetings
- Attend a Security Talk given by one of the security team
Information for developers
Security Bug Processes
Request a Security or Privacy Review
- Complete the questions at the following page to provide the basic info to kickstart a security or privacy review
- We'll create and link the corresponding wiki page within the Security Radar
- Security & Privacy Review Request Form
Contributing to the security of Mozilla products
There are a range of ways to contribute to security engineering at Mozilla.
- Implement security features
- Fix outstanding security bugs
- Contribute to security feature development
- Test Firefox or Mozilla Websites as part of our bug bounty programs
- Test & provide feedback on new security features
- Improve security documentation