Security: Difference between revisions

From MozillaWiki
Jump to navigation Jump to search
Line 20: Line 20:


[[Firefox Sync/Weave 1.3b5 Client Security Review]]
[[Firefox Sync/Weave 1.3b5 Client Security Review]]
''Firefox4:''
* [[Firefox/Projects/AccountManager/SecurityReview]]


===Security feature work===
===Security feature work===

Revision as of 22:43, 31 August 2010

Mozilla Security:

Welcome to the Mozilla Security wiki. There is not much here yet so feel free to contribute.

Security-related bugs

Security Severity Ratings

How to report a security issue

Want to fix a security bug? Here is a list of old thorny bugs you can take on.

Security reviews for new features/products

Firefox3.6/Security

Firefox3.5/Security

Labs/Weave/Sync Client Security Review

Firefox Sync/Weave 1.3b5 Client Security Review

Firefox4:

Security feature work

Main article: Security/Features

Content Security Policy proposal and implementation

Strict Transport Security proposal to prevent network attacks on all-HTTPS sites

Origin proposal for CSRF and clickjacking mitigation (i.e. anything that requires authentication of the origin of a request)

Process Isolation: Internal compartmentalization of Firefox architecture

Security Initiatives

Mozilla Security resources and blogs

Mozilla Security Center

Mozilla security developer docs

Mozilla Security blog

Lucas Adamski's blog

Sid Stamm's blog

Stuff that needs to be merged into this page properly