Security/FirefoxOperations: Difference between revisions

From MozillaWiki
Jump to navigation Jump to search
m (Fixed typo in my name ;))
 
(71 intermediate revisions by 3 users not shown)
Line 1: Line 1:
= Cloud Services Security Team =
= Firefox Operations Security =
Firefox Operations Security is responsible for application & operations security for internal & external services and websites in the Firefox organization that host sensitive data or provide a mission critical service.


The CloudSec team is tasked with securing core Firefox services operated by the Cloud Services organization at Mozilla.
[[File:Secops1024.png|400px|right]]


== Contact ==
== Contact ==
Email us at secops@mozilla.com.


Email us at cloudsec@mozilla.com with the PGP key [http://gpg.mozilla.org/pks/lookup?op=get&search=0xF7A9B793541A953D Mozilla Cloud Services Security (CloudSec) 6F73539153B31C193A2154EAF7A9B793541A953D]
To report a security issue on a given site, use the bug bounty form [https://www.mozilla.org/en-US/security/bug-bounty/faq-webapp/ as explained here].


The team is composed of [https://mozillians.org/en-US/u/jvehent/ Julien Vehent [:ulfr] ] and [https://mozillians.org/en-US/u/psiinon/ Simon Bennetts [:psiinon] ].
To tell us about a new service create a [https://github.com/mozilla-services/foxsec/issues/new?template=NewService.md&labels=New%20Service&assignee=psiinon&title=New%20Service:%20 New Service issue].


== Scope ==
__TOC__


CloudSec is responsible for the security of the following websites and backend services.
== Product Lines ==


(note: cloudsec is not responsible for the security of implementations in firefox, only of the backend services).
* Firefox Accounts
* Addons.mozilla.org
* Browser services (sync, push, normandy, remote settings, balrog, product delivery, etc.)
* Data services (telemetry, pioneer, taar, prio, etc.)
* Web presence of Premium services (FxSend, FxMonitor, FPN website, etc.)
* Release Engineering (taskcluster, shipit,  *.build.m.o, build infra, etc.)
* Developer Services (phabricator, lando, bugzilla, sentry, crash reports, etc.)


=== Addons.mozilla.org ===
== Scope ==
project: addons-server
 
=== Marketplace.firefox.com ===
project:
 
=== Product Delivery ===
project: go-bouncer
CDN: download-installer.cdn.mozilla.net
Bouncer: download.mozilla.org
 
=== Firefox Accounts ===
project: fxa
 
=== Firefox Sync ===
project: sync & tokenserver
 
=== Firefox Hello ===
project: loop & msisdn
 
=== Tracking Protection ===
project: shavar


=== Push ===
=== Application security ===
project: autopush
Responsibility for internal & external services and websites in the Firefox organization that host sensitive data or provide a mission critical service.
* Risk assessments
* Security Reviews
* Manual and automated testing
* Review risks w/ product owners
* Security incident management


=== Telemetry ===
The application security group also owns cryptographic services (autograph, tls canary, tls observatory, etc) and appsec tooling (zap, dependency observatory, etc.).


=== Persona ===
=== Operations security ===
project: persona
Responsibility for infrastructure and hosting of Firefox services.
* Covers the security of AWS and GCP infrastructure, and datacenters for the build infra
* Security operations consulting for the Firefox organization at large


=== Directory Tiles ===
The operations security group also owns the fraud pipeline (foxsec-pipeline) and secops tooling (frost, sops, etc.).
project: splice


=== TLS Observatory ===
=== Risk Management ===
project: tls-observatory
Responsibility for maintaining visibility into the security posture of the Firefox infrastructure.
* Rapid Risk Assessments framework & associated tooling
* Security posture reports & leadership reporting


=== ABSearch ===
== Security Checklist ==
project: absearch


=== Everything.me ===
This has moved to https://github.com/mozilla-services/websec-check


=== Find My Device ===
== About the logo ==


=== Location ===
The Firefox Operations Security logo is derived [https://github.com/synthagency/icons-flat-osx/blob/master/SVG/Apps-Firefox.svg from this work by Synth Agency], and published under Creative Commons Attribution-NonCommercial 4.0 International Public License.
project:

Latest revision as of 09:15, 22 January 2020

Firefox Operations Security

Firefox Operations Security is responsible for application & operations security for internal & external services and websites in the Firefox organization that host sensitive data or provide a mission critical service.

Secops1024.png

Contact

Email us at secops@mozilla.com.

To report a security issue on a given site, use the bug bounty form as explained here.

To tell us about a new service create a New Service issue.

Product Lines

  • Firefox Accounts
  • Addons.mozilla.org
  • Browser services (sync, push, normandy, remote settings, balrog, product delivery, etc.)
  • Data services (telemetry, pioneer, taar, prio, etc.)
  • Web presence of Premium services (FxSend, FxMonitor, FPN website, etc.)
  • Release Engineering (taskcluster, shipit, *.build.m.o, build infra, etc.)
  • Developer Services (phabricator, lando, bugzilla, sentry, crash reports, etc.)

Scope

Application security

Responsibility for internal & external services and websites in the Firefox organization that host sensitive data or provide a mission critical service.

  • Risk assessments
  • Security Reviews
  • Manual and automated testing
  • Review risks w/ product owners
  • Security incident management

The application security group also owns cryptographic services (autograph, tls canary, tls observatory, etc) and appsec tooling (zap, dependency observatory, etc.).

Operations security

Responsibility for infrastructure and hosting of Firefox services.

  • Covers the security of AWS and GCP infrastructure, and datacenters for the build infra
  • Security operations consulting for the Firefox organization at large

The operations security group also owns the fraud pipeline (foxsec-pipeline) and secops tooling (frost, sops, etc.).

Risk Management

Responsibility for maintaining visibility into the security posture of the Firefox infrastructure.

  • Rapid Risk Assessments framework & associated tooling
  • Security posture reports & leadership reporting

Security Checklist

This has moved to https://github.com/mozilla-services/websec-check

The Firefox Operations Security logo is derived from this work by Synth Agency, and published under Creative Commons Attribution-NonCommercial 4.0 International Public License.