Security/Meetings/SecurityAssurance/2013-05-07: Difference between revisions

Jump to navigation Jump to search
no edit summary
No edit summary
No edit summary
 
Line 77: Line 77:
|-
|-
|10 - 11am||||||||[https://security.etherpad.mozilla.org/malwarestategy Preventing malware in Firefox OS]|||
|10 - 11am||||||||[https://security.etherpad.mozilla.org/malwarestategy Preventing malware in Firefox OS]|||
|colspan="2"|[https://security.etherpad.mozilla.org/nsmNSM (Network Security Monitoring) Presentation & Workshop (mpurzynski)]
|rowspan="2"|[https://security.etherpad.mozilla.org/nsmNSM (Network Security Monitoring) Presentation & Workshop (mpurzynski)]||
|-
|-
| ||11 - noon||||||Product Security Roadmap (with Security Engineering)||||||
|11 - noon||||
|colspan="3"|[https://security.etherpad.mozilla.org/DiscussionOfSecEngRoadmap Product Security Roadmap (with Security Engineering)]
|-
|-
| Lunch||
| Lunch||
Line 86: Line 87:
|rowspan="4"|Afternoon
|rowspan="4"|Afternoon
|1pm - 2pm|
|1pm - 2pm|
|Q&A - Your career, HR questions, benefits, etc - w/ Emily Chardac
|[https://security.etherpad.mozilla.org/hrbp Q&A - Your career, HR questions, benefits, etc - w/ Emily Chardac]
|colspan="5" style="text-align: center;"|Open Team Work
|colspan="5" style="text-align: center;"|Open Team Work
|-
|-
|2pm - 3pm||||
|2pm - 3pm||||
|rowspan="2"|Static and Dynamic Analysis of JavaScript (2 hr workshop)
|rowspan="2"|Static and Dynamic Analysis of JavaScript (2 hr workshop)
||||Minion & Stooge Demos and brainstorm sessions||Security Alerting (gdestuynder)||
||||[https://security.etherpad.mozilla.org/minion-scanning-apis Minion & Stooge Demos and brainstorm sessions]||Security Alerting (gdestuynder)||
|-
|-
|3pm - 4pm||Incentivizing Security Fixes||||||||Collecting Logs (mhenry)||
|3pm - 4pm||[https://security.etherpad.mozilla.org/incentivizing-security-fixes Incentivizing Security Fixes]||||||||Collecting Logs (mhenry)||
|-
|-
|4pm - 5pm||Matt Wobensmith - Security QA||||||||||||
|4pm - 5pm||Matt Wobensmith - Security QA||||||||||||
Line 122: Line 123:
|-
|-
|rowspan="3"|Morning
|rowspan="3"|Morning
|9 - 10am||Security Automation - Discuss how to do more than Web Security||||||||||||
|9 - 10am||[https://security.etherpad.mozilla.org/security-automation Security Automation - Discuss how to do more than Web Security]||||||||||||
|-
|-
|10 - 11am||Endpoint security||||Fuzzing with WebIDL||||||||
|10 - 11am||[https://security.etherpad.mozilla.org/openmic Endpoint security]||||[https://security.etherpad.mozilla.org/FuzzingWithWebIDL Fuzzing with WebIDL]||||||||
|-
|-
|11 - noon
|11 - noon
Line 143: Line 144:
|3pm - 4pm||||||||||Identity Syncup||||
|3pm - 4pm||||||||||Identity Syncup||||
|-
|-
|4pm - 5pm||||A - Team : Clint Talbert||||Firefox OS Sandboxing w/ seccomp (kang)||||||
|4pm - 5pm||||[https://security.etherpad.mozilla.org/QAWithClintTalbert A - Team : Clint Talbert]||||Firefox OS Sandboxing w/ seccomp (kang)||||||
|-
|-
|Dinner||
|Dinner||
Line 173: Line 174:
|FYI - Manager hacking is 9-10am in SFO main area. Attend if interested.||||||||||
|FYI - Manager hacking is 9-10am in SFO main area. Attend if interested.||||||||||
|-
|-
|10 - 11am||||Review/Adjust Bug Risk Ranking / SecReview Process||||Fun in the TrustZone: what good is it to FxOS?||||
|10 - 11am||||[https://etherpad.mozilla.org/SecurityRiskRanking Review/Adjust Bug Risk Ranking / SecReview Process]||||["https://etherpad.mozilla.org/trustzone Fun in the TrustZone: what good is it to FxOS?]||||
|-
|-
|11 - noon||||||Fuzzing (Justice League)||Firefox OS Bug Bounty||Social API Review||Compliance checks - Cloud (AWS)||
|11 - noon||||||Fuzzing (Justice League)||[https://security.etherpad.mozilla.org/bugbountyfxos Firefox OS Bug Bounty]||[https://mana.mozilla.org/wiki/display/SECURITY/Social+API+multi-providers+Security+Review Social API Review]||[https://security.etherpad.mozilla.org/complianceaws Compliance checks - Cloud (AWS)]||
|-
|-
| Lunch||
| Lunch||
Line 217: Line 218:
|rowspan="3"|Morning
|rowspan="3"|Morning
|9 - 10am||
|9 - 10am||
||||||Fuzzing: logging||||Security Review Outputs||
||||||Fuzzing: logging||||[https://security.etherpad.mozilla.org/secreview-outputs Security Review Outputs]||
|-
|-
|10 - 11am||||||||Orangfuzz with orangutan (gkw) - pushed to 10.30am||||Multi Factor Authentication (kang)||
|10 - 11am||||||||[https://security.etherpad.mozilla.org/orangfuzzActions Orangfuzz with orangutan (gkw) - pushed to 10.30am]||||Multi Factor Authentication (kang)||
|-
|-
|11 - noon||||Malicious code in Firefox - Monitoring for suspicious code commits||||||||||
|11 - noon||||[https://docs.google.com/a/mozilla.com/document/d/1RvNAz1l0K_m1q4wWr9oYPg8KUq9-NTpFc0Dsh_IsfJo/edit Malicious code in Firefox - Monitoring for suspicious code commits]||||||||||
|-
|-
| Lunch||
| Lunch||
Line 228: Line 229:
|rowspan="4"|Afternoon
|rowspan="4"|Afternoon
|1pm - 2pm
|1pm - 2pm
|Google Security Visit||Open Team Work||||||||||
|Google Security Visit
|colspan="6"|Open Team Work
|-
|-
|2pm - 3pm||Google Security Visit||https://security.etherpad.mozilla.org/googleappstalk||||||||Asset discovery and vulnerability management (mhenry)||
|2pm - 3pm||Google Security Visit||[https://security.etherpad.mozilla.org/googleappstalk Google Notes]||||||||Asset discovery and vulnerability management (mhenry)||
|-
|-
|3pm - 3:30pm||Google Security Visit||||||||||||
|3pm - 3:30pm||Google Security Visit||||||||||||
canmove, Confirmed users, Bureaucrats and Sysops emeriti
2,776

edits

Navigation menu