SecurityEngineering/2013/Q4Goals: Difference between revisions

From MozillaWiki
Jump to navigation Jump to search
No edit summary
(Outcome of 10/10/2013 seceng meeting)
Line 1: Line 1:
{{draft}}
This quarter, every goal must have more than one person affiliated with and working on it.  There is still a DRI, but nobody is working alone.
This quarter, every goal must have more than one person affiliated with and working on it.  There is still a DRI, but nobody is working alone.
'''This is a lot of stuff.  We should consider making it smaller before locking them in.'''


* Sandboxing
* Sandboxing
Line 9: Line 5:
** DRI: sid (+keeler +christoph)
** DRI: sid (+keeler +christoph)
** Tasks:
** Tasks:
*** {{new|Implement: Chromium-sandbox}}: make it possible to compile and activate on mozilla-central - (keeler + christoph + bbondy)
*** {{new|Implement: Chromium-sandbox}}: make it possible to compile and activate on mozilla-central - (keeler + bbondy)
*** {{new|Consult: GFX-Remoting}} Form and document gpu-remoting plan (christoph + sid)
*** {{new|Implement: b2g/e10s security feature tests}}: Get CSP tests passing in e10s with help from overholt on platform team  (garrett + sid  + mwobensmith)
*** {{new|Implement: b2g/e10s security feature tests}}: Get CSP tests passing in e10s with help from overholt on platform team  (garrett + sid  + mwobensmith)


Line 30: Line 25:
* Mixed Content wrap up
* Mixed Content wrap up
** Outcome: Mixed script is blocked widely on the web in a stable way (and has no more urgent follow-ups.)
** Outcome: Mixed script is blocked widely on the web in a stable way (and has no more urgent follow-ups.)
** DRI: tanvi (+christoph)
** DRI: christoph (+tanvi)
** Tasks:
** Tasks:
*** {{ok|Implement: redirect bug}} - {{bug|418354}}
*** {{ok|Implement: redirect bug}} - {{bug|418354}}
*** {{ok|Implement: don't show mixed content on http pages}} - {{bug|909920}} (may require content policy api changes)
*** {{ok|Implement: don't show mixed content on http pages}} - {{bug|909920}} (may require content policy api changes)
*** {{ok|Implement: missing notification}} - {{bug|915951}}
*** {{ok|Implement: missing notification}} - {{bug|915951}}
*** {{ok|Implement:}} target = _parent - {{bug|906219}}
*** {{ok|Implement: persistency for child tabs}} - {{bug 906190}}


* CSP
* CSP
Line 43: Line 38:
*** {{ok|Implement: script nonce}} landed behind a pref.  {{bug|855326}}  (garrett + sid)
*** {{ok|Implement: script nonce}} landed behind a pref.  {{bug|855326}}  (garrett + sid)
*** {{ok|Implement: script hash}} landed behind a pref.  {{bug|883975}}  (garrett + sid)
*** {{ok|Implement: script hash}} landed behind a pref.  {{bug|883975}}  (garrett + sid)
*** {{ok|Evaluate: profile CSP}} on desktop and B2G to develop a plan to optimize CSP by rewriting in C++ or otherwise (https://bugzilla.mozilla.org/show_bug.cgi?id=924337#c26) [garrett + christoph]

Revision as of 00:37, 11 October 2013

This quarter, every goal must have more than one person affiliated with and working on it. There is still a DRI, but nobody is working alone.

  • Sandboxing
    • Outcome: Next set of steps towards a exploit-containing platform.
    • DRI: sid (+keeler +christoph)
    • Tasks:
      • [NEW] Implement: Chromium-sandbox: make it possible to compile and activate on mozilla-central - (keeler + bbondy)
      • [NEW] Implement: b2g/e10s security feature tests: Get CSP tests passing in e10s with help from overholt on platform team (garrett + sid + mwobensmith)
  • Roadmaps & user data storage plan
    • Outcome: More visibility and aim for our team's projects.
    • DRI: monica (+sid +garrett +cviecco +briansmith)
    • Tasks:
      • [NEW] Consult: security roadmap update (sid + briansmith + product teams)
      • [NEW] Consult: privacy roadmap update (monica + sid + product teams)
      • [NEW] Consult: anonymity (tor) roadmap update (sid + mikeperry)
  • NetSec
    • Outcome: Massive improvement in channel security for SSL sites that want protection from decryption.
    • DRI: briansmith (+cviecco)
    • Tasks:
      • [NEW] Land Insanity::PKIX - bug 878932 (briansmith + cviecco)
      • [NEW] Implement: TLS 1.2 enabled on nightly requires server intolerance + telemetry (cviecco + briansmith)
  • Mixed Content wrap up
    • Outcome: Mixed script is blocked widely on the web in a stable way (and has no more urgent follow-ups.)
    • DRI: christoph (+tanvi)
    • Tasks:
      • [ON TRACK] Implement: redirect bug - bug 418354
      • [ON TRACK] Implement: don't show mixed content on http pages - bug 909920 (may require content policy api changes)
      • [ON TRACK] Implement: missing notification - bug 915951
      • [ON TRACK] Implement: persistency for child tabs - Template:Bug 906190
  • CSP
    • Outcome: Wider adoption of CSP when Firefox supports these features (and beginning of CSP v1.1)
    • DRI: garrett (+sid)
    • Tasks: