Security/Reviews/B2GUpdates: Difference between revisions

Jump to navigation Jump to search
no edit summary
No edit summary
No edit summary
Line 68: Line 68:
* size is important
* size is important
|SecReview alt solutions=- Why three signatures?
|SecReview alt solutions=- Why three signatures?
* support for contractual relationships
* support for contractual relationships
- Who has final say in the case of disagreement?
- Who has final say in the case of disagreement on timing or content of updates?
* open question, to discuss with carriers
* open question, to discuss with carriers
|SecReview solution chosen=- Why three signatures?
|SecReview threat brainstorming=<b>Update is modified in transit or prior to being applied</b><br>
-  Who decides whay content will go into the final builds? (what happens  if for example, mozilla wants something carrier doesnt want?)
*SSL used for the update manifest (including hash of update content)
|SecReview threat brainstorming=*Update is modified prior to being applied
*Updates signed (potentially by all 3 keys)
**SSL used for the update manifest (including hash of update content)
 
**Updates signed (potentially by all 3 keys)
<b>Updates not available in timely fashion</b>
Updates not delivered in timely fashion
 
** How will chemspill process work, especially with three signing parties?
* How urgent update process will work is an open question, currently being negotiated with partners.
** Open question on how frequency will work with mulitple carriers. POssibly have gecko/gaia updates mozilla signed only.
** Open question on how frequency will work with multiple carriers. Possibly have Gecko/Gaia updates Mozilla signed only.
Open question:
 
Open questions:
Who will host updates?
Who will host updates?
Will users be able to get updates over wifi or usb?
Will users be able to get updates over WiFi or USB?
}}
}}
{{SecReviewActionStatus
{{SecReviewActionStatus
canmove, Confirmed users
1,220

edits

Navigation menu