<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.mozilla.org/index.php?action=history&amp;feed=atom&amp;title=Friends%2FEngineering</id>
	<title>Friends/Engineering - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.mozilla.org/index.php?action=history&amp;feed=atom&amp;title=Friends%2FEngineering"/>
	<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Friends/Engineering&amp;action=history"/>
	<updated>2026-08-17T03:30:32Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.10</generator>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Friends/Engineering&amp;diff=369381&amp;oldid=prev</id>
		<title>Smartin: /* Guidelines for Product Security */</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Friends/Engineering&amp;diff=369381&amp;oldid=prev"/>
		<updated>2011-11-15T00:38:23Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Guidelines for Product Security&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 00:38, 15 November 2011&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l3&quot;&gt;Line 3:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 3:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=Guidelines for Product Security=&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=Guidelines for Product Security=&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Privacy and Security Engineering is responsible for making sure the products we release are strong, secure, and adhere to our privacy principles.  In daily operation, following the Mozilla Privacy Principles are a core focus of these teams and drive much of our operation.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Privacy and Security Engineering is responsible for making sure the products we release are strong, secure, and adhere to our privacy principles.  In daily operation, following the Mozilla Privacy Principles are a core focus of these teams and drive much of our operation&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;.  These principles apply across all of Engineering&lt;/ins&gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Mozilla Privacy Principles==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Mozilla Privacy Principles==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Smartin</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Friends/Engineering&amp;diff=360155&amp;oldid=prev</id>
		<title>Sidstamm: Created page with &quot;Engineering is big, we could probably use a few more friends in engineering.  =Guidelines for Product Security=  Privacy and Security Engineering is responsible for making sure t...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Friends/Engineering&amp;diff=360155&amp;oldid=prev"/>
		<updated>2011-10-21T20:26:36Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;Engineering is big, we could probably use a few more friends in engineering.  =Guidelines for Product Security=  Privacy and Security Engineering is responsible for making sure t...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;Engineering is big, we could probably use a few more friends in engineering.&lt;br /&gt;
&lt;br /&gt;
=Guidelines for Product Security=&lt;br /&gt;
&lt;br /&gt;
Privacy and Security Engineering is responsible for making sure the products we release are strong, secure, and adhere to our privacy principles.  In daily operation, following the Mozilla Privacy Principles are a core focus of these teams and drive much of our operation.&lt;br /&gt;
&lt;br /&gt;
==Mozilla Privacy Principles==&lt;br /&gt;
&lt;br /&gt;
===No Surprises===&lt;br /&gt;
Always be open about how users&amp;#039; data is treated.  Ensure that the user is always in control of their data, even when the data is provided to improve security of a system (for example, Safe Browsing/antiphishing in Firefox).&lt;br /&gt;
&lt;br /&gt;
Collected data should be used only for the purposes for which users have granted us permission, always avoiding secondary (surprising) uses of the data.   By avoiding surprises, we build on our promise to users that it is their data, and they are in control.&lt;br /&gt;
&lt;br /&gt;
===Real Choices===&lt;br /&gt;
Ensure that users are not overwhelmed by decisions we ask them to make; it is not reasonable to expect them to be security experts and any prompts or questions asked of them should be in plain language and understandable by the majority of our user base.&lt;br /&gt;
&lt;br /&gt;
===Sensible Settings===&lt;br /&gt;
Prompting is not always a good idea when security decisions are complex.  We should use sensible defaults for most settings that users are unlikely to change.  Rationale for data collection or use should be outlined in a publicly accessible way (available and clear), but we should also not bother users needlessly.&lt;br /&gt;
&lt;br /&gt;
By choosing sensible defaults, we give users who aren&amp;#039;t privacy experts a head start towards understanding and controlling what happens to their data, and reduce the chance of surprises.&lt;br /&gt;
&lt;br /&gt;
===Limited Data===&lt;br /&gt;
Simply: if we don&amp;#039;t need to obtain it, don&amp;#039;t.  If we don&amp;#039;t need to keep it, don&amp;#039;t.  One of our focuses should be making sure that teams we work with only operate on the data needed for the task at hand.  Anything extra is a liability without any benefit.&lt;br /&gt;
&lt;br /&gt;
===User Control===&lt;br /&gt;
We should help our organization develop technologies that not only require less access to users&amp;#039;  data by Mozilla, but actually wrap it up in a way where the data can be  exposed only as absolutely necessary and as authorized directly by the user.&lt;br /&gt;
&lt;br /&gt;
===Trusted Third Parties===&lt;br /&gt;
When we enter into 3rd party transactions we should understand the privacy practices of the 3rd party and evaluate those against our principles.  Projects like safe browsing, crash reporting, and others that involve third parties should be driven in a way that extends to these parties the principles by which we operate.&lt;/div&gt;</summary>
		<author><name>Sidstamm</name></author>
	</entry>
</feed>