SecurityEngineering: Difference between revisions
(Containers is now a major effort) |
Ptheriault (talk | contribs) |
||
Line 7: | Line 7: | ||
==Who is involved== | ==Who is involved== | ||
Security Engineering is led by Richard Barnes and Steve Workman, | Security Engineering is led by [https://mozillians.org/en-US/u/rbarnes/ Richard Barnes] and [https://mozillians.org/en-US/u/sworkman/ Steve Workman]. Work is divided between two main teams: | ||
* Content Security Team: website & browser security features, DOM security (CSP, SRI, Cookies, origin etc), Content Blocking (safe browsing, download protection) | |||
* Communications security: TLS stack, communications security, Crypto APIs, [[PSM:Topics|PSM]] | |||
==How We Work== | ==How We Work== |
Revision as of 02:47, 29 July 2016
We build security and user sovereignty into Firefox. Through this work, we encourage and promote these values on the open web.
We focus hard on ways to improve the privacy and security of all web users, in a Mozilla way that engages the community in our design and implementation decisions. These priorities are reflected in the projects this team manages, public evangelism and participation in relevant standards bodies to maximize adoption of new privacy & security mechanisms.
The open web is powerful; the huge number of people working on web standards and software is astonishing, and the rapid advancement of new businesses and technologies online magnifies the need for advances in mechanisms that enable secure systems and users' control over their presence online.
Who is involved
Security Engineering is led by Richard Barnes and Steve Workman. Work is divided between two main teams:
- Content Security Team: website & browser security features, DOM security (CSP, SRI, Cookies, origin etc), Content Blocking (safe browsing, download protection)
- Communications security: TLS stack, communications security, Crypto APIs, PSM
How We Work
The Security Engineering team works publicly like other Mozilla engineering teams. Continuously, we are focused on four top-level activities:
- Implement and Deploy
- Consult on Architecture and Design
- Research new Ideas
- Evangelize what we do
For more details, check out our strategy.
Major Efforts
Add-on signing | Daniel Veditz |
Application Reputation | Francois Marier |
CA Program | Kathleen Wilson |
Containers | Tanvi Vyas |
Content Security Policy | Christoph Kerschbaumer |
Error Reporting | Mark Goodwin |
Meta Referrer | |
Mixed Content Blocking | Tanvi Vyas |
OneCRL | Mark Goodwin |
Password Manager | Tanvi Vyas |
Revamp of Security Hooks | Christoph Kerschbaumer |
Safe Browsing | Francois Marier |
Sub-resource Integrity | Francois Marier |
Tor bugs | Dave Huseby |
Tracking Protection | Francois Marier |
How to participate
Discuss: We hang out on #security and #contentsecurity on irc.mozilla.org, and our primary mailing list is mozilla.dev.security.
Follow our work: To see our current progress against features please see the Mozilla Security Blog.
Do some reviews:
- Add "seceng waiting for reviews" to your Bugzilla preferences
- See our SecurityEngineering/CodeReviewGuidelines
Contribute: Wanna pitch in, maybe do a project? Check out the good first bugs list and if one interests you, contact us!
Experimental Things
We have a few feature proposals for things we might want to add to Firefox but that aren't currently scheduled:
- Contextual Identity
- Foreign Certificate Warning
- Master Password in the Password Manager
- private sessions and user profiles
- Automatic Private Browsing Upgrades
From time to time we make add-ons to try out experimental features. Here are a few; let us know what you think!
Security Bugs
If you've found a security bug please see http://www.mozilla.org/security/#For_Developers