Changes

Jump to: navigation, search

Security

3,502 bytes removed, 01:18, 14 February 2012
Undo revision 396985 by Mcoates (talk)
<p>Welcome to the Mozilla Security wiki. There is not much here yet so feel free to contribute.</p><h3> === Security-related bugs </h3><ul><li> &lt;a _fcknotitle="true" href="=* [[Security Severity Ratings"&gt;Security Severity Ratings&lt;/a&gt; ]] </li><li> &lt;a href="* [http://www.mozilla.org/security/#For_Developers"&gt;How to report a security issue&lt;/a&gt; ] </li><li> &lt;a href="* [[Security/FixMe"&gt;|Want to fix a security bug? Here is a list of old thorny bugs you can take on.&lt;/a&gt;]]</li></ul><h3>===Security reviews for new features/products</h3>===<p><i>''Main Article: &lt;a _fcknotitle="true" href="Security/Reviews"&gt;[[Security/Reviews&lt;/a&gt;</i>]]''</p><ul><li> * Find past reviews by &lt;a href="[https://wiki.mozilla.org/Category:SecReview"&gt;Category:SecReview&lt;/a&gt;]</li></ul><h4>&lt;a href="===[[Security/Radar"&gt;|Security Radar&lt;/a&gt;</h4>]]==== <table {| class="wikitable collapsible collapsed" style="width: 100%"><tr><th> ! Unlinked Reviews</th></tr><tr>|-<td>|<ul><li> &lt;a href="* [[Security/Reviews/Mobile/AndroidSystemStorage"&gt; | Android System Storage&lt;/a&gt;]]</li><li> &lt;a href="* [[Security/Firefox/WebAPI/WebBattery"&gt; | WebBattery&lt;/a&gt;]]</li><li> &lt;a href="* [[Security/Reviews/BrowserIDCAPI"&gt; | BrowserID C API&lt;/a&gt;]]</li><li> &lt;a href="* [[Security/Reviews/crossoriginAttribute"&gt;|Add crossorigin attribute&lt;/a&gt;]]</li><li> &lt;a href="* [[Security/Reviews/Firefox10/SyncDialogue"&gt;|Sync Dialogue&lt;/a&gt;]]</li><li> &lt;a href="* [[Security/Reviews/JetPack2011-20/12"&gt; | JetPack 2011-10-12&lt;/a&gt;]]</li><li> &lt;a href="* [[Security/Reviews/XHRnonpost"&gt; | XHR non-post rewrite&lt;/a&gt;]]</li><li> &lt;a href="* [[Security/Reviews/StubInstaller"&gt;|Stub Installer&lt;/a&gt;]]</li><li> &lt;a href="* [[Labs/Weave/Sync Client Security Review"&gt;|Sync Client&lt;/a&gt;]]</li><li> &lt;a href="* [[Firefox Sync/Weave 1.3b5 Client Security Review"&gt;|Weave 1.3b5 Client&lt;/a&gt;]]</li><li> &lt;a href="* [[Security/Reviews/DNSSEC-TLS"&gt;|DNSSEC-TLS&lt;/a&gt;]]</li><li> &lt;a href="* [[Security/Reviews/OWA-F1"&gt;|Web Activities &amp; F1&lt;/a&gt;]]</li><li> &lt;a href="* [[Security/Reviews/ReviewNotes/MouseLock"&gt;|MouseLock&lt;/a&gt;]]</li><li> &lt;a href="* [[Security/Reviews/ReviewNotes/Joystick"&gt;|Joystick&lt;/a&gt;]]</li></ul>|}</td></tr></table><table {| class="wikitable collapsible collapsed" style="width: 100%"><tr><th> ! Unlinked Discusions</th></tr><tr>|-<td>|<ul><li> &lt;a href="* [[Security/Discussions/WebRTC"&gt;|WebRTC&lt;/a&gt;]]</li></ul>|}</td></tr></table><h3>===Security Feature Development</h3>=== <p><i>''Main article: &lt;a _fcknotitle="true" href="[[Security/Roadmap"&gt;Security/Roadmap&lt;/a&gt;</i>]]'' </p><p><i>''Main article: &lt;a _fcknotitle="true" href="Privacy/Roadmap"&gt;[[Privacy/Roadmap&lt;/a&gt;</i>]]''</p><h3> === Security Initiatives </h3><ul><li>&lt;a _fcknotitle="true" href="Security/TeamEmbedding"&gt;= *[[Security/TeamEmbedding&lt;/a&gt;]]</li><li>*Prioritizing and driving non-feature work: &lt;a _fcknotitle="true" href="Security/Driving"&gt;[[Security/Driving&lt;/a&gt;]]</li></ul><h3> === Security Resources and Blogs </h3>=== <h4> ==== Mozilla Official Sites </h4>====<ul><li> &lt;a href="* [http://www.mozilla.org/security"&gt;Mozilla Security Center&lt;/a&gt;]</li><li> &lt;a href="* [http://developer.mozilla.org/en/Security"&gt;Mozilla security developer docs&lt;/a&gt;]</li><li> &lt;a href="* [[CA"&gt;|Mozilla CA Root Program&lt;/a&gt;]]</li><li> &lt;a href="* [http://blog.mozilla.com/security"&gt;Mozilla Security blog&lt;/a&gt;]</li><li> &lt;a href="* [http://blog.mozilla.com/webappsec"&gt;Mozilla WebApp Sec Blog&lt;/a&gt;]</li><li> &lt;a href="* [https://wiki.mozilla.org/WebAppSec/Secure_Coding_Guidelines"&gt;Secure Coding Guidelines for Webapps&lt;/a&gt;]</li></ul>
<h4> Personal Security Related Blogs of Mozillians </h4>
<ul><li> &lt;a href="http://blog.mozilla.com/ladamski"&gt;Lucas Adamski's blog&lt;/a&gt;
</li><li> &lt;a href="http://blog.mozilla.com/decoder"&gt;Christian Holler's blog (decoder)&lt;/a&gt;
</li></ul>
<h4> Twitter Accounts of Security Mozillians </h4>
<ul><li> &lt;a href="https://twitter.com/mozsec"&gt;Mozilla Security&lt;/a&gt;
</li><li> &lt;a href="https://twitter.com/mozwebsec"&gt;Mozilla Security&lt;/a&gt;
</li><li> &lt;a href="https://twitter.com/jruderman"&gt;Jesse Ruderman&lt;/a&gt;
</li><li> &lt;a href="https://twitter.com/curtisko"&gt;Curtis Koenig&lt;/a&gt; (all kinds of random stuff)
</li><li> &lt;a href="https://twitter.com/_mwc"&gt;Michael Coates&lt;/a&gt;
</li><li> &lt;a href="https://twitter.com/flamsmark"&gt;Tom Lowenthal&lt;/a&gt; (privacy)
</li><li> &lt;a href="https://twitter.com/securitae"&gt;Lucas Adamski&lt;/a&gt;
</li><li> &lt;a href="https://twitter.com/alexanderfowler"&gt;Alex Fowler&lt;/a&gt;
</li><li> &lt;a href="https://twitter.com/ygjb"&gt;Yvan Boily&lt;/a&gt;
</li><li> &lt;a href="https://twitter.com/dveditz"&gt;Daniel Veditz&lt;/a&gt;
</li><li> &lt;a href="https://twitter.com/openbuddha"&gt;Al Billings&lt;/a&gt; (but mostly Buddhist and Hackerspace tweets)
</li><li> &lt;a href="https://twitter.com/imelven"&gt;Ian Melven&lt;/a&gt;
</li><li> &lt;a href="https://twitter.com/kangsterizer"&gt;Guillaume Destuynder&lt;/a&gt;
</li><li> &lt;a href="https://twitter.com/nth10sd"&gt;Gary Kwong&lt;/a&gt; (all sorts of stuff)
</li><li> &lt;a href="https://twitter.com/mozdeco"&gt;Christian Holler (decoder)&lt;/a&gt;
</li></ul>
<h4> Non-Mozilla Resources (blogs, news sites, twitter, tools) </h4>
<ul><li> &lt;a href="Security/OtherSecurityResources"&gt; Other Security Resources&lt;/a&gt;
</li></ul>
<h3>Stuff that needs to be merged into this page properly</h3>
<h3> Meeting Notes </h3>
<h4>SecTeam Meetings</h4>
<table class="wikitable collapsible collapsed" style="width: 100%">
<tr>
<th> Meetings
</th></tr>
<tr>
<td>
<table class="wikitable collapsible collapsed" style="width: 100%">
<tr>
<th> AppSec Meetings 2012
</th></tr>
<tr>
<td>
<ul><li> &lt;a href="Security/AppSecBiweekly/2012-02-13"&gt;2012-02-13&lt;/a&gt;
</li></ul>
</td></tr></table>
<table class="wikitable collapsible collapsed" style="width: 100%">
<tr>
<th> SecTeam Meetings 2012
</th></tr>
<tr>
<td>
<ul><li> &lt;a href="Security/Meetings/2012-02-01"&gt;2012-02-01&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2012-01-25"&gt;2012-01-25&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2012-01-18"&gt;2012-01-18&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2012-01-11"&gt;2012-01-11&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2012-01-04"&gt;2012-01-04&lt;/a&gt;
</li></ul>
</td></tr></table>
<table class="wikitable collapsible collapsed" style="width: 100%">
<tr>
<th> SecTeam Meetings 2011
</th></tr>
<tr>
<td>
<ul><li> &lt;a href="Security/Meetings/2011-12-28"&gt;2011-12-28&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-12-21"&gt;2011-12-21&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-12-07"&gt;2011-12-14&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-12-07"&gt;2011-12-07&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-11-30"&gt;2011-11-30&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-11-23"&gt;2011-11-23&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-11-16"&gt;2011-11-16&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-11-09"&gt;2011-11-09&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-11-02"&gt;2011-11-02&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-10-26"&gt;2011-10-26&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-10-19"&gt;2011-10-19&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-10-12"&gt;2011-10-12&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-10-05"&gt;2011-10-05&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-09-28"&gt;2011-09-28&lt;/a&gt;
</li><li> No meeting on 9/14 (All Hands) or 9/21 (Fuzzing Work Week)
</li><li> &lt;a href="Security/Meetings/2011-09-07"&gt;2011-09-07&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-08-31"&gt;2011-08-31&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-08-24"&gt;2011-08-24&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/lifecycledisc"&gt;Life Cycle discussion&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-08-17"&gt;2011-08-17&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-08-10"&gt;2011-08-10&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-07-27"&gt;2011-07-27&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-07-20"&gt;2011-07-20&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-07-13"&gt;2011-07-13&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-07-06"&gt;2011-07-06&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-06-29"&gt;2011-06-29&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-06-22"&gt;2011-06-22&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-06-15"&gt;2011-06-15&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-06-08"&gt;2011-06-08&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-06-01"&gt;2011-06-01&lt;/a&gt;
</li></ul>
</td></tr></table>
<table class="wikitable collapsible collapsed" style="width: 100%">
<tr>
<th> Joint Secteam-Infrasec Meetings 2012
</th></tr>
<tr>
<td>
<ul><li> &lt;a href="Security/Meetings/2012-01-12"&gt;2012-01-12&lt;/a&gt;
</li></ul>
</td></tr></table>
<table class="wikitable collapsible collapsed" style="width: 100%">
<tr>
<th> Joint Secteam-Infrasec Meetings 2011
</th></tr>
<tr>
<td>
<ul><li> &lt;a href="Security/Meetings/2011-12-15"&gt;2011-12-15&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-11-17"&gt;2011-11-17&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-10-06"&gt;2011-10-06&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-09-08"&gt;2011-09-08&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-08-25"&gt;2011-08-25&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-08-11"&gt;2011-08-11&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-07-28"&gt;2011-07-28&lt;/a&gt;
</li><li> &lt;a href="Security/Meetings/2011-06-16"&gt;2011-06-16&lt;/a&gt;
</li></ul>
</td></tr></table>
</td></tr></table>
<p><br />
</p>
<p><br />
</p>
 
==== Twitter Accounts of Security Mozillians ====
* [https://twitter.com/mozsec Mozilla Security]
* [https://twitter.com/mozwebsec Mozilla Security]
* [https://twitter.com/jruderman Jesse Ruderman]
* [https://twitter.com/curtisko Curtis Koenig] (all kinds of random stuff)
* [https://twitter.com/_mwc Michael Coates]
* [https://twitter.com/flamsmark Tom Lowenthal] (privacy)
* [https://twitter.com/securitae Lucas Adamski]
* [https://twitter.com/alexanderfowler Alex Fowler]
* [https://twitter.com/ygjb Yvan Boily]
* [https://twitter.com/dveditz Daniel Veditz]
* [https://twitter.com/openbuddha Al Billings] (but mostly Buddhist and Hackerspace tweets)
* [https://twitter.com/imelven Ian Melven]
* [https://twitter.com/kangsterizer Guillaume Destuynder]
* [https://twitter.com/nth10sd Gary Kwong] (all sorts of stuff)
* [https://twitter.com/mozdeco Christian Holler (decoder)]
 
==== Non-Mozilla Resources (blogs, news sites, twitter, tools) ====
* [[Security/OtherSecurityResources| Other Security Resources]]
 
===Stuff that needs to be merged into this page properly===
 
=== Meeting Notes ===
====SecTeam Meetings====
{| class="wikitable collapsible collapsed" style="width: 100%"
! Meetings
|-
|
{| class="wikitable collapsible collapsed" style="width: 100%"
! AppSec Meetings 2012
|-
|
* [[Security/AppSecBiweekly/2012-02-13|2012-02-13]]
|}
{| class="wikitable collapsible collapsed" style="width: 100%"
! SecTeam Meetings 2012
|-
|
* [[Security/Meetings/2012-02-01|2012-02-01]]
* [[Security/Meetings/2012-01-25|2012-01-25]]
* [[Security/Meetings/2012-01-18|2012-01-18]]
* [[Security/Meetings/2012-01-11|2012-01-11]]
* [[Security/Meetings/2012-01-04|2012-01-04]]
|}
{| class="wikitable collapsible collapsed" style="width: 100%"
! SecTeam Meetings 2011
|-
|
* [[Security/Meetings/2011-12-28|2011-12-28]]
* [[Security/Meetings/2011-12-21|2011-12-21]]
* [[Security/Meetings/2011-12-07|2011-12-14]]
* [[Security/Meetings/2011-12-07|2011-12-07]]
* [[Security/Meetings/2011-11-30|2011-11-30]]
* [[Security/Meetings/2011-11-23|2011-11-23]]
* [[Security/Meetings/2011-11-16|2011-11-16]]
* [[Security/Meetings/2011-11-09|2011-11-09]]
* [[Security/Meetings/2011-11-02|2011-11-02]]
* [[Security/Meetings/2011-10-26|2011-10-26]]
* [[Security/Meetings/2011-10-19|2011-10-19]]
* [[Security/Meetings/2011-10-12|2011-10-12]]
* [[Security/Meetings/2011-10-05|2011-10-05]]
* [[Security/Meetings/2011-09-28|2011-09-28]]
* No meeting on 9/14 (All Hands) or 9/21 (Fuzzing Work Week)
* [[Security/Meetings/2011-09-07|2011-09-07]]
* [[Security/Meetings/2011-08-31|2011-08-31]]
* [[Security/Meetings/2011-08-24|2011-08-24]]
* [[Security/Meetings/lifecycledisc|Life Cycle discussion]]
* [[Security/Meetings/2011-08-17|2011-08-17]]
* [[Security/Meetings/2011-08-10|2011-08-10]]
* [[Security/Meetings/2011-07-27|2011-07-27]]
* [[Security/Meetings/2011-07-20|2011-07-20]]
* [[Security/Meetings/2011-07-13|2011-07-13]]
* [[Security/Meetings/2011-07-06|2011-07-06]]
* [[Security/Meetings/2011-06-29|2011-06-29]]
* [[Security/Meetings/2011-06-22|2011-06-22]]
* [[Security/Meetings/2011-06-15|2011-06-15]]
* [[Security/Meetings/2011-06-08|2011-06-08]]
* [[Security/Meetings/2011-06-01|2011-06-01]]
|}
 
{| class="wikitable collapsible collapsed" style="width: 100%"
! Joint Secteam-Infrasec Meetings 2012
|-
|
* [[Security/Meetings/2012-01-12|2012-01-12]]
|}
{| class="wikitable collapsible collapsed" style="width: 100%"
! Joint Secteam-Infrasec Meetings 2011
|-
|
 
* [[Security/Meetings/2011-12-15|2011-12-15]]
* [[Security/Meetings/2011-11-17|2011-11-17]]
* [[Security/Meetings/2011-10-06|2011-10-06]]
* [[Security/Meetings/2011-09-08|2011-09-08]]
* [[Security/Meetings/2011-08-25|2011-08-25]]
* [[Security/Meetings/2011-08-11|2011-08-11]]
* [[Security/Meetings/2011-07-28|2011-07-28]]
* [[Security/Meetings/2011-06-16|2011-06-16]]
|}
|}
Confirm
491
edits

Navigation menu