SecurityEngineering/MeetingNotes/02-07-13: Difference between revisions

Jump to navigation Jump to search
no edit summary
No edit summary
Line 12: Line 12:
* we discussed things that are only important to CA/SSL -types.
* we discussed things that are only important to CA/SSL -types.


== Mixed Content ==
= Mixed Content =
=== Needed to Turn the Pref on in Hopefully FF 21 by Feb 18th ==
== Needed to Turn the Pref on in Hopefully FF 21 by Feb 18th ==
* https://bugzilla.mozilla.org/show_bug.cgi?id=834836 - Turn pref on by default - Need to fix tests.
* https://bugzilla.mozilla.org/show_bug.cgi?id=834836 - Turn pref on by default - Need to fix tests.
* https://bugzilla.mozilla.org/show_bug.cgi?id=781018 - Telemetry and try uplifting to 19, 20 and 21.
* https://bugzilla.mozilla.org/show_bug.cgi?id=781018 - Telemetry and try uplifting to 19, 20 and 21.
=== Before Beta ===
== Before Beta ==
* https://bugzilla.mozilla.org/show_bug.cgi?id=837351 - Webconsole + Error Console alerts when Mixed Content is Blocked -  needs updated patch
* https://bugzilla.mozilla.org/show_bug.cgi?id=837351 - Webconsole + Error Console alerts when Mixed Content is Blocked -  needs updated patch
* https://bugzilla.mozilla.org/show_bug.cgi?id=839238 - Lots of Documentation  
* https://bugzilla.mozilla.org/show_bug.cgi?id=839238 - Lots of Documentation  
Line 25: Line 25:
* https://bugzilla.mozilla.org/show_bug.cgi?id=836431 - distinguish between mixed active vs mixed display loads in Webconsole - https://developer.mozilla.org/en-US/docs/Security/MixedContent
* https://bugzilla.mozilla.org/show_bug.cgi?id=836431 - distinguish between mixed active vs mixed display loads in Webconsole - https://developer.mozilla.org/en-US/docs/Security/MixedContent
* https://bugzilla.mozilla.org/show_bug.cgi?id=418354, and https://bugzilla.mozilla.org/show_bug.cgi?id=456957  - Block https->http redirects.
* https://bugzilla.mozilla.org/show_bug.cgi?id=418354, and https://bugzilla.mozilla.org/show_bug.cgi?id=456957  - Block https->http redirects.
=== the rest: ===
== The Rest: ==
* https://bugzilla.mozilla.org/show_bug.cgi?id=838403 - Missing call for setting flag for mixed display blocked - needs a test.
* https://bugzilla.mozilla.org/show_bug.cgi?id=838403 - Missing call for setting flag for mixed display blocked - needs a test.
* https://bugzilla.mozilla.org/show_bug.cgi?id=836811 - needs a test, but has already landed in central
* https://bugzilla.mozilla.org/show_bug.cgi?id=836811 - needs a test, but has already landed in central
Line 33: Line 33:
** Inconsistency between first time visitor and second time visitors to an hsts embedded page.
** Inconsistency between first time visitor and second time visitors to an hsts embedded page.
** https://blog.mozilla.org/ embeds http://blog.mozilla.org/files/2013/01/most-trusted-privacy-2012-252x218.jpg that redirects to the https version.
** https://blog.mozilla.org/ embeds http://blog.mozilla.org/files/2013/01/most-trusted-privacy-2012-252x218.jpg that redirects to the https version.
** What shoudl the correct behavior be?
** What should the correct behavior be?
* https://bugzilla.mozilla.org/show_bug.cgi?id=826599 - users have a choice to disable mixed content on iframes.  What should the correct behavior be?
* https://bugzilla.mozilla.org/show_bug.cgi?id=826599 - users have a choice to disable mixed content on iframes.  What should the correct behavior be?
* v2 Technical Information section that shows what is blocked.
* v2 Technical Information section that shows what is blocked.
* UI tweeks
* UI tweaks
** Make mixed content blocker more discoverable - https://bugzilla.mozilla.org/show_bug.cgi?id=834828
** Make mixed content blocker more discoverable - https://bugzilla.mozilla.org/show_bug.cgi?id=834828
** Strike through https - https://bugzilla.mozilla.org/show_bug.cgi?id=834830
** Strike through https - https://bugzilla.mozilla.org/show_bug.cgi?id=834830
** UI Redesign Tweaks - https://bugzilla.mozilla.org/show_bug.cgi?id=827595
** UI Redesign Tweaks - https://bugzilla.mozilla.org/show_bug.cgi?id=827595
== research! ==
= Research! =
* password stats - https://docs.google.com/a/mozilla.com/spreadsheet/ccc?key=0AnujPp0bAzAvdDhVTnZuSTROamcwSGh0aGRZSDJNdmc#gid=6
* password stats - https://docs.google.com/a/mozilla.com/spreadsheet/ccc?key=0AnujPp0bAzAvdDhVTnZuSTROamcwSGh0aGRZSDJNdmc#gid=6
= Internship/Mentorship project brainstorming =
= Internship/Mentorship project brainstorming =
Confirmed users
197

edits

Navigation menu