Security: Difference between revisions

From MozillaWiki
Jump to navigation Jump to search
Line 12: Line 12:


===Security reviews for new features/products===
===Security reviews for new features/products===
''Main Article: [[Security/Reviews]]''


[[Firefox3.6/Security]]
[[Labs/Weave/Sync Client Security Review|Sync Client]]


[[Firefox3.5/Security]]
[[Firefox Sync/Weave 1.3b5 Client Security Review|Weave 1.3b5 Client]]


[[Labs/Weave/Sync Client Security Review]]
[[Firefox/Projects/AccountManager/SecurityReview|Account Manager]]
 
[[Firefox Sync/Weave 1.3b5 Client Security Review]]
 
''Firefox4:''
* [[Firefox/Projects/AccountManager/SecurityReview]]


===Security feature work===
===Security feature work===

Revision as of 20:51, 15 September 2010

Mozilla Security:

Welcome to the Mozilla Security wiki. There is not much here yet so feel free to contribute.

Security-related bugs

Security Severity Ratings

How to report a security issue

Want to fix a security bug? Here is a list of old thorny bugs you can take on.

Security reviews for new features/products

Main Article: Security/Reviews

Sync Client

Weave 1.3b5 Client

Account Manager

Security feature work

Main article: Security/Features

Content Security Policy proposal and implementation

Strict Transport Security proposal to prevent network attacks on all-HTTPS sites

Origin proposal for CSRF and clickjacking mitigation (i.e. anything that requires authentication of the origin of a request)

Process Isolation: Internal compartmentalization of Firefox architecture

Security Initiatives

Mozilla Security resources and blogs

Mozilla Security Center

Mozilla security developer docs

Mozilla Security blog

Lucas Adamski's blog

Sid Stamm's blog

Stuff that needs to be merged into this page properly