Confirmed users
717
edits
| Line 63: | Line 63: | ||
|- | |- | ||
! Item | ! Item | ||
! Owner | ! Owner | ||
|- | |- | ||
| [https://wiki.mozilla.org/NPAPI:Pepper2 Plugin sandboxing]<br> | | [https://wiki.mozilla.org/NPAPI:Pepper2 Plugin sandboxing]<br> | ||
| ? | | ? | ||
|- | |- | ||
| [https://groups.google.com/group/mozilla.dev.security/browse_thread/thread/f8afac1eef7cb4cd/b570280627c3dca8 Effective certificate revocation and management]<br> | | [https://groups.google.com/group/mozilla.dev.security/browse_thread/thread/f8afac1eef7cb4cd/b570280627c3dca8 Effective certificate revocation and management]<br> | ||
| ? | | ? | ||
|- | |- | ||
| [https://wiki.mozilla.org/Opt-in_activation_for_plugins Plugin runtime mitigations such as whitelist and/or click to ]<br> | | [https://wiki.mozilla.org/Opt-in_activation_for_plugins Plugin runtime mitigations such as whitelist and/or click to ]<br> | ||
| | | Justin Dolske | ||
|- | |- | ||
| javascript: and data: handling in URL bar and chrome | | javascript: and data: handling in URL bar and chrome | ||
| <br> | | <br> | ||
|- | |- | ||
| DLL whitelisting by name or signature<br> | | DLL whitelisting by name or signature<br> | ||
| ?<br> | | ?<br> | ||
|- | |- | ||
| Track "Application Reputation"<br> | | Track "Application Reputation"<br> | ||
| <br> | | <br> | ||
|- | |- | ||
| Prune dead and dying code<br> | | Prune dead and dying code<br> | ||
| <br> | | <br> | ||
|- | |- | ||
| Malloc should be infallible<br> | | Malloc should be infallible<br> | ||
| <br> | | <br> | ||
|- | |- | ||
| TLS 1.2 support<br> | | TLS 1.2 support<br> | ||
| <br> | | <br> | ||
|- | |- | ||
| Eviltraps meta-bug (prevents users from leaving a page)<br> | | Eviltraps meta-bug (prevents users from leaving a page)<br> | ||
| <br> | | <br> | ||
|- | |- | ||
| Notify user of malware in their crash signatures<br> | | Notify user of malware in their crash signatures<br> | ||
| <br> | | <br> | ||
|- | |- | ||
| Expose HSTS and other security browser state to plugins (NPAPI)<br> | | Expose HSTS and other security browser state to plugins (NPAPI)<br> | ||
| <br> | | <br> | ||
|- | |- | ||
| Ignore autocomplete="off" for password fields | | Ignore autocomplete="off" for password fields | ||
| <br> | | <br> | ||
|- | |- | ||
| UX security experiment | | UX security experiment | ||
| ? | | ? | ||
|- | |- | ||
| [https://bugzilla.mozilla.org/show_bug.cgi?id=663566 Content Security Policy revisions] | | [https://bugzilla.mozilla.org/show_bug.cgi?id=663566 Content Security Policy revisions] | ||
| Brandon Sterne | | Brandon Sterne | ||
|- | |- | ||
| CSRF mitigations | | CSRF mitigations | ||
| <br> | | <br> | ||
|- | |- | ||
| Clickjacking mitigations | | Clickjacking mitigations | ||
| | | | ||
|- | |- | ||
| X-Content-Type-Options | | X-Content-Type-Options | ||
| | | | ||
|- | |- | ||
| toStaticHTML | | toStaticHTML | ||
| | | | ||
|} | |} | ||