Security/B2G/2013 3 20: Difference between revisions

From MozillaWiki
< Security‎ | B2G
Jump to navigation Jump to search
(Created page with "==FirefoxOS Security Team Meeting== 1pm PST, B2G Vidyo room Prior notes are here: https://wiki.mozilla.org/Security/B2G/2013_2_20 http://cansecwest.com/slides/2013/Adobe%20Sandbo...")
 
 
(One intermediate revision by the same user not shown)
Line 3: Line 3:
Prior notes are here:
Prior notes are here:
https://wiki.mozilla.org/Security/B2G/2013_2_20
https://wiki.mozilla.org/Security/B2G/2013_2_20
http://cansecwest.com/slides/2013/Adobe%20Sandbox.pdf
 
===News ===
===News ===
Upcoming features:
Upcoming features:
*
* interesting paper http://cansecwest.com/slides/2013/Adobe%20Sandbox.pdf
 
=== Current/upcoming Reviews===
=== Current/upcoming Reviews===
=== Goal Status Updates ===
=== Goal Status Updates ===
====1. FirefoxOS related security reviews (owner: pauljt)====
====1. FirefoxOS related security reviews (owner: pauljt)====
Not here
Not here
====2. Document Firefox OS Security (owner: dchan)====
====2. Document Firefox OS Security (owner: dchan)====
Mostly done:
https://developer.mozilla.org/en-US/docs/Mozilla/Firefox_OS/Security


    freddy did some appsec-testing docs
Needs work:
 
https://developer.mozilla.org/en-US/docs/Mozilla/Firefox_OS/Security/Application_security
    Part 1: https://developer.mozilla.org/en-US/docs/Mozilla/Firefox_OS/Debugging_and_Security_Testing_with_Firefox_OS
https://developer.mozilla.org/en-US/docs/Mozilla/Firefox_OS/Debugging_and_Security_Testing_with_Firefox_OS
 
    Part2: https://developer.mozilla.org/en-US/docs/Mozilla/Firefox_OS/Intercept_Firefox_OS_Traffic_Using_a_Proxy
 
    Part 3: I'm not really happy with it, so it's in mana (scroll down): https://mana.mozilla.org/wiki/display/SECURITY/2013+Q1+-+Frederik+Braun+-+Learn+B2G
 
    https://developer.mozilla.org/en-US/docs/Mozilla/Firefox_OS/Security/System_security (some parts of this are still in Security_Model)
 
    talk to sheppy for help irc://#mdn
 
    #mdn can rename, make editorial reviews


====3. Develop and land tests for security features (owner: dchan)====
====3. Develop and land tests for security features (owner: dchan)====

Latest revision as of 20:35, 19 March 2013

FirefoxOS Security Team Meeting

1pm PST, B2G Vidyo room Prior notes are here: https://wiki.mozilla.org/Security/B2G/2013_2_20

News

Upcoming features:

Current/upcoming Reviews

Goal Status Updates

1. FirefoxOS related security reviews (owner: pauljt)

Not here

2. Document Firefox OS Security (owner: dchan)

Mostly done: https://developer.mozilla.org/en-US/docs/Mozilla/Firefox_OS/Security

Needs work: https://developer.mozilla.org/en-US/docs/Mozilla/Firefox_OS/Security/Application_security https://developer.mozilla.org/en-US/docs/Mozilla/Firefox_OS/Debugging_and_Security_Testing_with_Firefox_OS

3. Develop and land tests for security features (owner: dchan)

Working on finishing up suite 2 https://bugzilla.mozilla.org/show_bug.cgi?id=815105 Fixed up code to work again

4.Engage communities & third-parties for Firefox OS security review and testing (owner: pauljt)

https://docs.google.com/a/mozilla.com/document/d/1_KbifvJMxddhFsNbiHE5AwyNpFnIQNcVcmMkJ_QtvUw/edit#

5. Drive OS-layer security improvement (owner: kang)

- ASLR being reviewed, still needs some work for a cleaner implementation in gecko - Still trying to acquire qualcom sources for unagi

6. Secure app developer/reviewer guidelines/tools (owner: rforbes)

https://docs.google.com/a/mozilla.com/document/d/1DLs1jhTMxN5fh2PSb_O7FDaSadjjAW-MlK1xCBRWGmM/edit#

Other Items