SummerOfCode/2013/SecurityReport/WeeklyUpdates/2013-06-03: Difference between revisions

(Created page with "{{subst:WeeklyUpdates}}")
 
 
(4 intermediate revisions by the same user not shown)
Line 1: Line 1:
<small>[[WeeklyUpdates/{{#time:Y-m-d|{{SUBPAGENAME}} -1 week}}|« previous week]] | [[WeeklyUpdates|index]] | [[WeeklyUpdates/{{#time:Y-m-d|{{SUBPAGENAME}} +1 week}}|next week »]]</small>
{{conf|8600}}
__TOC__
= All-hands Status Meeting Agenda =
Items in this section will be shared during the live all-hand status meeting.
== Friends of the Tree [[Image:Tree.gif|Friends of the Tree]] ==
== Upcoming Events ==


=== This Week ===
=== This Week ===
Line 21: Line 7:


=== Wednesday, {{#time:d F|{{SUBPAGENAME}} +2 days}} ===
=== Wednesday, {{#time:d F|{{SUBPAGENAME}} +2 days}} ===
* Created a rough phase wise plan of project after discussing with my mentor.
  1. Record different types of security errors from various locations in the browser (such as error console, web console) and display them at a single location.
  2. Create a UI to display security errors. We can first start with an extension and then integrate it into developers tool. Alternatively, we can directly start with integration into developers tool.
  3. Do a large scale study of web site (for example, Alexa 1M top websites) to check how many sites have security errors or bad practices. Publish our survey result in good venue.
  4. Allow users to take decisions. Infer CSP policy for a website and offer users inferred policy if the website doesn't set a CSP policy.


=== Thursday, {{#time:d F|{{SUBPAGENAME}} +3 days}} ===
=== Thursday, {{#time:d F|{{SUBPAGENAME}} +3 days}} ===
The first step to start project is to list down the things that need to be included in security report tool.


=== Friday, {{#time:d F|{{SUBPAGENAME}} +4 days}} ===
* A list of Security Errors and Warnings that can be included in the security report tool.
  i) CSP violation
  ii) mixed content blocking
  iii) SSL errors
  iV) CORS (Cross Origin Resource Request)


=== Saturday, {{#time:d F|{{SUBPAGENAME}} +5 days}} ===
Additional information that can be collected:
  i) http-only field missing
  ii) X-Frame-Options header missing
  iii) HSTS
  iv) CSP header missing


=== Sunday, {{#time:d F|{{SUBPAGENAME}} +6 days}} ===
=== Friday, {{#time:d F|{{SUBPAGENAME}} +4 days}} ===
 
=== Next Week ===
 
== Product Status Updates (voice updates) ==
 
=== Firefox Desktop ===
''Speaker Location:''
 
=== Firefox Mobile ===
''Speaker Location:''
 
=== Thunderbird ===
''Speaker Location:''
 
=== Older Branch Work ===
''Speaker Location:''
 
=== Webmaker ===
''Speaker Location:''
 
=== Identity ===
''Speaker Location:''
 
=== Services ===
''Speaker Location:''
 
=== Firefox OS ===
''Speaker Location:''
 
=== Grow Mozilla ===
''Speaker Location:''
 
== Speakers ==
 
The limit is 3 minutes per speaker.  It's like a lightning talk, but don't feel that you have to have slides in order to make a presentation.  If you plan on showing a video, you need to contact the Air Mozilla team before the day of the meeting or you will be deferred to the next week.
 
{| class="fullwidth-table"
|-
!  Presenter
!  Title
!  Topic
!  Location
!  Share?
!  Media
!  More Details
|-
| Who Are You?
| What Do You Do?
| What are you going to talk about?
| Where are you presenting from? (Moz Space, your house, space)
| Will you be sharing your screen? (yes/no, other info)
| Links to slides or images you want displayed on screen
| Link to where audience can find out more information
|-
|}
 
== Introducing New Hires ==
{| class="fullwidth-table"
|-
!  New Hire
!  Introduced by
!  Speaker location
!  New Hire location
!  Will be working on
|-
| ''Who is the new hire?''
| ''Who will be introducing that person?''
| ''From which office will that introduction be transmitted?''
| ''Where will the new person be working from?''
| ''What will the new person be working on?''
|-
<!-- Insert new rows here -->
|-
|}
 
== Introducing New Interns ==
{| class="fullwidth-table"
|-
!  New Intern
!  Introduced by
!  Speaker location
!  New Hire location
!  Will be working on
|-
| ''Who is the new intern?''
| ''Who will be introducing that person?''
| ''From which office will that introduction be transmitted?''
| ''Where will the new person be working from?''
| ''What will the new person be working on?''
|-
<!-- Insert new rows here -->
|-
|}
 
== Roundtable ==
 
= &lt;meta&gt; =
 
Notes and non-voice status updates that aren't part of the live meeting go here.
 
== Status Updates By Team (*non-voice* updates) ==
 
=== Firefox ===
 
=== Platform ===
 
=== Services ===
 
=== Messaging ===
 
=== Mobile ===
 
=== IT ===
 
=== Release Engineering ===
 
=== QA ===
 
==== Test Execution ====
 
==== WebQA ====
 
==== QA Community ====
 
=== Automation & Tools ===
 
=== Security ===
 
=== Engagement ===
 
==== PR ====
 
==== Events ====
 
==== Creative Team ====
 
==== Community Marketing ====
 
=== Support ===
 
=== Metrics ===
 
=== Evangelism ===
 
=== Labs ===
 
=== Apps ===
 
=== Developer Tools ===
 
=== Add-ons ===
 
=== Webdev ===
 
=== L10n ===
 
=== People Team ===
 
=== WebFWD ===
 
== Foundation Updates ==

Latest revision as of 03:54, 7 June 2013

This Week

Monday, 03 June

Tuesday, 04 June

Wednesday, 05 June

  • Created a rough phase wise plan of project after discussing with my mentor.
 1. Record different types of security errors from various locations in the browser (such as error console, web console) and display them at a single location.
 2. Create a UI to display security errors. We can first start with an extension and then integrate it into developers tool. Alternatively, we can directly start with integration into developers tool. 
 3. Do a large scale study of web site (for example, Alexa 1M top websites) to check how many sites have security errors or bad practices. Publish our survey result in good venue.
 4. Allow users to take decisions. Infer CSP policy for a website and offer users inferred policy if the website doesn't set a CSP policy.

Thursday, 06 June

The first step to start project is to list down the things that need to be included in security report tool.

  • A list of Security Errors and Warnings that can be included in the security report tool.
  i) CSP violation
  ii) mixed content blocking
  iii) SSL errors
  iV) CORS (Cross Origin Resource Request)

Additional information that can be collected:

  i) http-only field missing
  ii) X-Frame-Options header missing
  iii) HSTS
  iv) CSP header missing

Friday, 07 June