Changes

Jump to: navigation, search

Security

3,502 bytes added, 01:16, 14 February 2012
Undo revision 396984 by Mcoates (talk)
<p>Welcome to the Mozilla Security wiki. There is not much here yet so feel free to contribute.</p>=== <h3> Security-related bugs </h3><ul><li> &lt;a _fcknotitle="true" href==* [["Security Severity Ratings"&gt;Security Severity Ratings]] &lt;/a&gt; * [</li><li> &lt;a href="http://www.mozilla.org/security/#For_Developers "&gt;How to report a security issue] &lt;/a&gt; * [[</li><li> &lt;a href="Security/FixMe|"&gt;Want to fix a security bug? Here is a list of old thorny bugs you can take on.]]&lt;/a&gt;</li></ul>===<h3>Security reviews for new features/products===</h3>''<p><i>Main Article: [[&lt;a _fcknotitle="true" href="Security/Reviews"&gt;Security/Reviews]]''&lt;/a&gt;</i>* </p><ul><li> Find past reviews by [&lt;a href="https://wiki.mozilla.org/Category:SecReview "&gt;Category:SecReview]&lt;/a&gt;</li></ul><h4>&lt;a href====[["Security/Radar|"&gt;Security Radar]]====&lt;/a&gt;</h4>{| <table class="wikitable collapsible collapsed" style="width: 100%">! <tr><th> Unlinked Reviews|-</th></tr><tr>|<td>* [[<ul><li> &lt;a href="Security/Reviews/Mobile/AndroidSystemStorage| "&gt; Android System Storage]]&lt;/a&gt;* [[</li><li> &lt;a href="Security/Firefox/WebAPI/WebBattery| "&gt; WebBattery]]&lt;/a&gt;* [[</li><li> &lt;a href="Security/Reviews/BrowserIDCAPI| "&gt; BrowserID C API]]&lt;/a&gt;* [[</li><li> &lt;a href="Security/Reviews/crossoriginAttribute|"&gt;Add crossorigin attribute]]&lt;/a&gt;* [[</li><li> &lt;a href="Security/Reviews/Firefox10/SyncDialogue|"&gt;Sync Dialogue]]&lt;/a&gt;* [[</li><li> &lt;a href="Security/Reviews/JetPack2011-20/12 | "&gt; JetPack 2011-10-12]]&lt;/a&gt;* [[</li><li> &lt;a href="Security/Reviews/XHRnonpost| "&gt; XHR non-post rewrite]]&lt;/a&gt;* [[</li><li> &lt;a href="Security/Reviews/StubInstaller|"&gt;Stub Installer]]&lt;/a&gt;* [[</li><li> &lt;a href="Labs/Weave/Sync Client Security Review|"&gt;Sync Client]]&lt;/a&gt;* [[</li><li> &lt;a href="Firefox Sync/Weave 1.3b5 Client Security Review|"&gt;Weave 1.3b5 Client]]&lt;/a&gt;* [[</li><li> &lt;a href="Security/Reviews/DNSSEC-TLS|"&gt;DNSSEC-TLS]]&lt;/a&gt;* [[</li><li> &lt;a href="Security/Reviews/OWA-F1|"&gt;Web Activities & amp; F1]]&lt;/a&gt;* [[</li><li> &lt;a href="Security/Reviews/ReviewNotes/MouseLock|"&gt;MouseLock]]&lt;/a&gt;* [[</li><li> &lt;a href="Security/Reviews/ReviewNotes/Joystick|"&gt;Joystick]]&lt;/a&gt;|}</li></ul></td></tr></table>{| <table class="wikitable collapsible collapsed" style="width: 100%"><tr>! <th> Unlinked Discusions|-</th></tr><tr>|<td>* [[<ul><li> &lt;a href="Security/Discussions/WebRTC|"&gt;WebRTC]]&lt;/a&gt;|}</li></ul></td></tr></table>===<h3>Security Feature Development===</h3> ''<p><i>Main article: [[&lt;a _fcknotitle="true" href="Security/Roadmap]]''"&gt;Security/Roadmap&lt;/a&gt;</i> ''</p><p><i>Main article: [[&lt;a _fcknotitle="true" href="Privacy/Roadmap"&gt;Privacy/Roadmap]]''&lt;/a&gt;</i></p>=== <h3> Security Initiatives </h3><ul><li>&lt;a _fcknotitle="true" href== *[["Security/TeamEmbedding"&gt;Security/TeamEmbedding]]&lt;/a&gt;*</li><li>Prioritizing and driving non-feature work: [[&lt;a _fcknotitle="true" href="Security/Driving"&gt;Security/Driving]]&lt;/a&gt;</li></ul>=== <h3> Security Resources and Blogs ===</h3>==== <h4> Mozilla Official Sites </h4><ul><li> &lt;a href====* ["http://www.mozilla.org/security "&gt;Mozilla Security Center]&lt;/a&gt;* [</li><li> &lt;a href="http://developer.mozilla.org/en/Security "&gt;Mozilla security developer docs]&lt;/a&gt;* [[</li><li> &lt;a href="CA|"&gt;Mozilla CA Root Program]]&lt;/a&gt;* [</li><li> &lt;a href="http://blog.mozilla.com/security "&gt;Mozilla Security blog]&lt;/a&gt;* [</li><li> &lt;a href="http://blog.mozilla.com/webappsec "&gt;Mozilla WebApp Sec Blog]&lt;/a&gt;* [</li><li> &lt;a href="https://wiki.mozilla.org/WebAppSec/Secure_Coding_Guidelines "&gt;Secure Coding Guidelines for Webapps]&lt;/a&gt;</li></ul>
<h4> Personal Security Related Blogs of Mozillians </h4>
<ul><li> &lt;a href="http://blog.mozilla.com/ladamski"&gt;Lucas Adamski's blog&lt;/a&gt;
</li><li> &lt;a href="http://blog.mozilla.com/decoder"&gt;Christian Holler's blog (decoder)&lt;/a&gt;
</li></ul>
<h4> Twitter Accounts of Security Mozillians </h4>
<ul><li> &lt;a href="https://twitter.com/mozsec"&gt;Mozilla Security&lt;/a&gt;
</li><li> &lt;a href="https://twitter.com/mozwebsec"&gt;Mozilla Security&lt;/a&gt;
</li><li> &lt;a href="https://twitter.com/jruderman"&gt;Jesse Ruderman&lt;/a&gt;
</li><li> &lt;a href="https://twitter.com/curtisko"&gt;Curtis Koenig&lt;/a&gt; (all kinds of random stuff)
</li><li> &lt;a href="https://twitter.com/_mwc"&gt;Michael Coates&lt;/a&gt;
</li><li> &lt;a href="https://twitter.com/flamsmark"&gt;Tom Lowenthal&lt;/a&gt; (privacy)
</li><li> &lt;a href="https://twitter.com/securitae"&gt;Lucas Adamski&lt;/a&gt;
</li><li> &lt;a href="https://twitter.com/alexanderfowler"&gt;Alex Fowler&lt;/a&gt;
</li><li> &lt;a href="https://twitter.com/ygjb"&gt;Yvan Boily&lt;/a&gt;
</li><li> &lt;a href="https://twitter.com/dveditz"&gt;Daniel Veditz&lt;/a&gt;
</li><li> &lt;a href="https://twitter.com/openbuddha"&gt;Al Billings&lt;/a&gt; (but mostly Buddhist and Hackerspace tweets)
</li><li> &lt;a href="https://twitter.com/imelven"&gt;Ian Melven&lt;/a&gt;
</li><li> &lt;a href="https://twitter.com/kangsterizer"&gt;Guillaume Destuynder&lt;/a&gt;
</li><li> &lt;a href="https://twitter.com/nth10sd"&gt;Gary Kwong&lt;/a&gt; (all sorts of stuff)
</li><li> &lt;a href="https://twitter.com/mozdeco"&gt;Christian Holler (decoder)&lt;/a&gt;
</li></ul>
<h4> Non-Mozilla Resources (blogs, news sites, twitter, tools) </h4>
<ul><li> &lt;a href="Security/OtherSecurityResources"&gt; Other Security Resources&lt;/a&gt;
</li></ul>
<h3>Stuff that needs to be merged into this page properly</h3>
<h3> Meeting Notes </h3>
<h4>SecTeam Meetings</h4>
<table class="wikitable collapsible collapsed" style="width: 100%">
<tr>
<th> Meetings
</th></tr>
<tr>
<td>
<table class="wikitable collapsible collapsed" style="width: 100%">
<tr>
<th> AppSec Meetings 2012
</th></tr>
<tr>
<td>
<ul><li> &lt;a href="Security/AppSecBiweekly/2012-02-13"&gt;2012-02-13&lt;/a&gt;
</li></ul>
</td></tr></table>
<table class="wikitable collapsible collapsed" style="width: 100%">
<tr>
<th> SecTeam Meetings 2012
</th></tr>
<tr>
<td>
<ul><li> &lt;a href="Security/Meetings/2012-02-01"&gt;2012-02-01&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2012-01-25"&gt;2012-01-25&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2012-01-18"&gt;2012-01-18&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2012-01-11"&gt;2012-01-11&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2012-01-04"&gt;2012-01-04&lt;/a&gt;
</li></ul>
</td></tr></table>
<table class="wikitable collapsible collapsed" style="width: 100%">
<tr>
<th> SecTeam Meetings 2011
</th></tr>
<tr>
<td>
<ul><li> &lt;a href="Security/Meetings/2011-12-28"&gt;2011-12-28&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-12-21"&gt;2011-12-21&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-12-07"&gt;2011-12-14&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-12-07"&gt;2011-12-07&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-11-30"&gt;2011-11-30&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-11-23"&gt;2011-11-23&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-11-16"&gt;2011-11-16&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-11-09"&gt;2011-11-09&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-11-02"&gt;2011-11-02&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-10-26"&gt;2011-10-26&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-10-19"&gt;2011-10-19&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-10-12"&gt;2011-10-12&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-10-05"&gt;2011-10-05&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-09-28"&gt;2011-09-28&lt;/a&gt;
</li><li> No meeting on 9/14 (All Hands) or 9/21 (Fuzzing Work Week)
</li><li> &lt;a href="Security/Meetings/2011-09-07"&gt;2011-09-07&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-08-31"&gt;2011-08-31&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-08-24"&gt;2011-08-24&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/lifecycledisc"&gt;Life Cycle discussion&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-08-17"&gt;2011-08-17&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-08-10"&gt;2011-08-10&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-07-27"&gt;2011-07-27&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-07-20"&gt;2011-07-20&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-07-13"&gt;2011-07-13&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-07-06"&gt;2011-07-06&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-06-29"&gt;2011-06-29&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-06-22"&gt;2011-06-22&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-06-15"&gt;2011-06-15&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-06-08"&gt;2011-06-08&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-06-01"&gt;2011-06-01&lt;/a&gt;
</li></ul>
</td></tr></table>
<table class="wikitable collapsible collapsed" style="width: 100%">
<tr>
<th> Joint Secteam-Infrasec Meetings 2012
</th></tr>
<tr>
<td>
<ul><li> &lt;a href="Security/Meetings/2012-01-12"&gt;2012-01-12&lt;/a&gt;
</li></ul>
</td></tr></table>
<table class="wikitable collapsible collapsed" style="width: 100%">
<tr>
<th> Joint Secteam-Infrasec Meetings 2011
</th></tr>
<tr>
<td>
<ul><li> &lt;a href="Security/Meetings/2011-12-15"&gt;2011-12-15&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-11-17"&gt;2011-11-17&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-10-06"&gt;2011-10-06&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-09-08"&gt;2011-09-08&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-08-25"&gt;2011-08-25&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-08-11"&gt;2011-08-11&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-07-28"&gt;2011-07-28&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-06-16"&gt;2011-06-16&lt;/a&gt;
</li></ul>
</td></tr></table>
</td></tr></table>
<p><br />
</p>
<p><br />
</p>
 
==== Twitter Accounts of Security Mozillians ====
* [https://twitter.com/mozsec Mozilla Security]
* [https://twitter.com/mozwebsec Mozilla Security]
* [https://twitter.com/jruderman Jesse Ruderman]
* [https://twitter.com/curtisko Curtis Koenig] (all kinds of random stuff)
* [https://twitter.com/_mwc Michael Coates]
* [https://twitter.com/flamsmark Tom Lowenthal] (privacy)
* [https://twitter.com/securitae Lucas Adamski]
* [https://twitter.com/alexanderfowler Alex Fowler]
* [https://twitter.com/ygjb Yvan Boily]
* [https://twitter.com/dveditz Daniel Veditz]
* [https://twitter.com/openbuddha Al Billings] (but mostly Buddhist and Hackerspace tweets)
* [https://twitter.com/imelven Ian Melven]
* [https://twitter.com/kangsterizer Guillaume Destuynder]
* [https://twitter.com/nth10sd Gary Kwong] (all sorts of stuff)
* [https://twitter.com/mozdeco Christian Holler (decoder)]
 
==== Non-Mozilla Resources (blogs, news sites, twitter, tools) ====
* [[Security/OtherSecurityResources| Other Security Resources]]
 
===Stuff that needs to be merged into this page properly===
 
=== Meeting Notes ===
====SecTeam Meetings====
{| class="wikitable collapsible collapsed" style="width: 100%"
! Meetings
|-
|
{| class="wikitable collapsible collapsed" style="width: 100%"
! AppSec Meetings 2012
|-
|
* [[Security/AppSecBiweekly/2012-02-13|2012-02-13]]
|}
{| class="wikitable collapsible collapsed" style="width: 100%"
! SecTeam Meetings 2012
|-
|
* [[Security/Meetings/2012-02-01|2012-02-01]]
* [[Security/Meetings/2012-01-25|2012-01-25]]
* [[Security/Meetings/2012-01-18|2012-01-18]]
* [[Security/Meetings/2012-01-11|2012-01-11]]
* [[Security/Meetings/2012-01-04|2012-01-04]]
|}
{| class="wikitable collapsible collapsed" style="width: 100%"
! SecTeam Meetings 2011
|-
|
* [[Security/Meetings/2011-12-28|2011-12-28]]
* [[Security/Meetings/2011-12-21|2011-12-21]]
* [[Security/Meetings/2011-12-07|2011-12-14]]
* [[Security/Meetings/2011-12-07|2011-12-07]]
* [[Security/Meetings/2011-11-30|2011-11-30]]
* [[Security/Meetings/2011-11-23|2011-11-23]]
* [[Security/Meetings/2011-11-16|2011-11-16]]
* [[Security/Meetings/2011-11-09|2011-11-09]]
* [[Security/Meetings/2011-11-02|2011-11-02]]
* [[Security/Meetings/2011-10-26|2011-10-26]]
* [[Security/Meetings/2011-10-19|2011-10-19]]
* [[Security/Meetings/2011-10-12|2011-10-12]]
* [[Security/Meetings/2011-10-05|2011-10-05]]
* [[Security/Meetings/2011-09-28|2011-09-28]]
* No meeting on 9/14 (All Hands) or 9/21 (Fuzzing Work Week)
* [[Security/Meetings/2011-09-07|2011-09-07]]
* [[Security/Meetings/2011-08-31|2011-08-31]]
* [[Security/Meetings/2011-08-24|2011-08-24]]
* [[Security/Meetings/lifecycledisc|Life Cycle discussion]]
* [[Security/Meetings/2011-08-17|2011-08-17]]
* [[Security/Meetings/2011-08-10|2011-08-10]]
* [[Security/Meetings/2011-07-27|2011-07-27]]
* [[Security/Meetings/2011-07-20|2011-07-20]]
* [[Security/Meetings/2011-07-13|2011-07-13]]
* [[Security/Meetings/2011-07-06|2011-07-06]]
* [[Security/Meetings/2011-06-29|2011-06-29]]
* [[Security/Meetings/2011-06-22|2011-06-22]]
* [[Security/Meetings/2011-06-15|2011-06-15]]
* [[Security/Meetings/2011-06-08|2011-06-08]]
* [[Security/Meetings/2011-06-01|2011-06-01]]
|}
 
{| class="wikitable collapsible collapsed" style="width: 100%"
! Joint Secteam-Infrasec Meetings 2012
|-
|
* [[Security/Meetings/2012-01-12|2012-01-12]]
|}
{| class="wikitable collapsible collapsed" style="width: 100%"
! Joint Secteam-Infrasec Meetings 2011
|-
|
 
* [[Security/Meetings/2011-12-15|2011-12-15]]
* [[Security/Meetings/2011-11-17|2011-11-17]]
* [[Security/Meetings/2011-10-06|2011-10-06]]
* [[Security/Meetings/2011-09-08|2011-09-08]]
* [[Security/Meetings/2011-08-25|2011-08-25]]
* [[Security/Meetings/2011-08-11|2011-08-11]]
* [[Security/Meetings/2011-07-28|2011-07-28]]
* [[Security/Meetings/2011-06-16|2011-06-16]]
|}
|}
Confirm
491
edits

Navigation menu