Changes

Jump to: navigation, search

Security/Sandbox

921 bytes removed, 18:19, 27 July 2017
eol whiteboard bug lists
*** printing tests
*** roll out level 3 to release
** Need to scope out future milestones including:
*** using an alternate desktop
*** using an alternate winstation and desktop
*** general file system (and registry) read access restrictions (USER_RESTRICTED / UESR_LOCKDOWN)
*** JOB_LOCKDOWN
*** reducing exposure to system APIs
*** running at untrusted integrity level
*** use of lowbox token / AppContainers
* OSX Content Process
*** file:/// isolation
*** roll out level2 OSX sandbox to release
** [https://bugzilla.mozilla.org/buglist.cgi?quicksearch=whiteboard%3Asbmc3 sbmc3]
*** TBD: Triage existing sandbox rules and define set to remove in milestone 3
*** File access: system /tmp and /var/folders/ and any other individual directories
*** Limit User directory file access
* Linux Content Process
*** file:/// isolation?
*** remote pulseaudio work (BLOCKED on media work, TBD)
** [https://bugzilla.mozilla.org/buglist.cgi?quicksearch=whiteboard%3Asblc4 sblc4]
*** remove/restrict socket access/modification and solve X11 problem
** [https://bugzilla.mozilla.org/buglist.cgi?quicksearch=whiteboard%3Asblc5 sblc5]
*** make use of chroot and user namespaces
* Windows 64-bit NPAPI
Confirm
1,982
edits

Navigation menu