SecurityEngineering/2013/Q3Goals: Difference between revisions

From MozillaWiki
Jump to navigation Jump to search
Line 33: Line 33:
** Tasks:
** Tasks:
*** Implement : {{new|Land app reputation system with whitelist support}}
*** Implement : {{new|Land app reputation system with whitelist support}}
*** Implement : {{new|Switch SafeBrowsing to use HTTPS}}

Revision as of 20:45, 30 July 2013

Q3 Goals

  • [CARRY OVER] Finish first phase of Sandboxing
    • Outcome: seccomp in e10s/Larch or on nightly + clear roadmap
    • DRI: Sid
    • Tasks:
      • Consult : E10S contributions to make it reasonably usable in nightly. (without extensions/plugins)
      • Implement : [NEW] Fix window.crypto to work in E10S
      • Implement : [NEW] Fix CSP tests to work in E10S
      • Implement : [NEW] land seccomp for Linux (min bar for sandboxing)
      • Research : [NEW] Prioritize secomp tightening steps, begin executing it
      • Research : [NEW] Create story/plan for addon compatibility (also see evilpie's doc)
  • [NEW] Cookie Clearinghouse
    • Outcome: Identify feasibility and nail down spec
    • DRI: Monica
    • Tasks:
      • Implement : [NEW] spec out and make go/nogo decision on implementation
      • Consult : [NEW] drive Stanford effort to stable spec


  • [CARRY OVER] Implement alternative revocation checking mechanisms
    • Outcome: must-staple + pinning + insanity on by default in nightly
    • DRI: Camilo
    • Tasks:
      • Implement : [NEW] Enable insanity::pkix validation by default on nightly
      • Implement : [NEW] Land key pinning
      • Implement : [NEW] Land must-staple support


  • [CARRY OVER] SafeBrowsing 2.0
    • Outcome: App reputation whitelist on by default in nightly
    • DRI: Monica
    • Tasks:
      • Implement : [NEW] Land app reputation system with whitelist support