Security: Difference between revisions

From MozillaWiki
Jump to navigation Jump to search
Line 24: Line 24:
''Main article: [[Security/Features]]''
''Main article: [[Security/Features]]''


[[Security/CSP|Content Security Policy]] proposal and implementation
* [[Security/CSP|Content Security Policy]] proposal and implementation
 
* [[Security/STS|Strict Transport Security]] proposal to prevent network attacks on all-HTTPS sites
[[Security/STS|Strict Transport Security]] proposal to prevent network attacks on all-HTTPS sites
* [[Security/Origin|Origin proposal for CSRF and clickjacking mitigation]]  (i.e. anything that requires authentication of the origin of a request)
 
* [[Security/ProcessIsolation|Process Isolation: Internal compartmentalization of Firefox architecture]]
[[Security/Origin|Origin proposal for CSRF and clickjacking mitigation]]  (i.e. anything that requires authentication of the origin of a request)
 
[[Security/ProcessIsolation|Process Isolation: Internal compartmentalization of Firefox architecture]]


=== Security Initiatives ===
=== Security Initiatives ===

Revision as of 20:52, 15 September 2010

Mozilla Security:

Welcome to the Mozilla Security wiki. There is not much here yet so feel free to contribute.

Security-related bugs

Security Severity Ratings

How to report a security issue

Want to fix a security bug? Here is a list of old thorny bugs you can take on.

Security reviews for new features/products

Main Article: Security/Reviews

Sync Client

Weave 1.3b5 Client

Account Manager

Security feature work

Main article: Security/Features

Security Initiatives

Mozilla Security resources and blogs

Mozilla Security Center

Mozilla security developer docs

Mozilla Security blog

Lucas Adamski's blog

Sid Stamm's blog

Stuff that needs to be merged into this page properly