SecurityEngineering/2015/Q1Goals: Difference between revisions

From MozillaWiki
Jump to navigation Jump to search
(→‎Content Security: Added Content Security Goals)
(→‎Tracking Protection: Added Tracking Protection Goals)
Line 13: Line 13:


== Tracking Protection ==
== Tracking Protection ==
TODO
* {{new|Get TP UI enabled in Nightly/Aurora to check webcompat, shake out bugs etc.}} (dri=mmc)
* {{new|Review Referrer Policy.}} (dri=mmc/sid)
* {{new|Start experimenting with Containers for Contextual Identity.}} (dri=mmc)
* {{new|Tor bugs.}} (dri=sid)
* {{new|Blog post for meta referrer.}} (dri=Sid)


== Addon Security ==
== Addon Security ==

Revision as of 21:21, 6 January 2015


DRAFT DRAFT DRAFT DRAFT DRAFT

Content Security

  • [NEW] Decide on Security Engineering Proposals for Password Manager: Local Encryption, Autofill, Passwords on HTTP pages (dri=tanvi)
    • (NOTE: This is temporarily vague and should be clearer early in Q1: Blocked on (soon-to-be-made) Firefox Product decisions).
  • [NEW] REVAMP: Finalize LoadInfo patches for JS/C++ gecko channels . (dri=ckerschb)
  • [NEW] REVAMP: Start implementing the LoadInfo shim for addons. (dri=ckerschb)
  • [NEW] CSP: Prototype CSP devtool that provides suggested policy for page. (dri=ckerschb)
  • [NEW] Land SRI with style support. (dri=francois)
  • [NEW] Propose an approach for adding reporting to SRI. (dri=francois)

Tracking Protection

  • [NEW] Get TP UI enabled in Nightly/Aurora to check webcompat, shake out bugs etc. (dri=mmc)
  • [NEW] Review Referrer Policy. (dri=mmc/sid)
  • [NEW] Start experimenting with Containers for Contextual Identity. (dri=mmc)
  • [NEW] Tor bugs. (dri=sid)
  • [NEW] Blog post for meta referrer. (dri=Sid)

Addon Security

TODO

Communications Security

TODO

QE (tracking)

TODO