SecurityEngineering/2013: Difference between revisions

From MozillaWiki
Jump to navigation Jump to search
No edit summary
 
Line 27: Line 27:
* Implement: Rewrite certificate verification library ({{bug|878932}})
* Implement: Rewrite certificate verification library ({{bug|878932}})
* Implement: Certificate key pinning ({{bug|744204}})
* Implement: Certificate key pinning ({{bug|744204}})
* Research/Evangelize/Implement: [https://wiki.mozilla.org/CA CA inclusion/maintenance policy v2.1]
* Research/Evangelize/Implement: [https://wiki.mozilla.org/CA:CertificatePolicyV2.1 Certificate Policy] to raise the bar on intermediate CAs
* Research/Implement: [https://addons.mozilla.org/en-US/firefox/addon/password-knight/ Password Knight]
* Research/Implement: [https://addons.mozilla.org/en-US/firefox/addon/password-knight/ Password Knight]
* Research/Implement: [[Security/Features/SSL_Error_Reporting|Certificate error reporting]]
* Research/Implement: [[Security/Features/SSL_Error_Reporting|Certificate error reporting]]

Latest revision as of 18:34, 19 June 2013

Working towards our team Strategy, this is what we will work towards in 2013.

Make Firefox More Secure

Build Security and Privacy into Mobile

Improve User Control Over How Their Information is Shared and Used

  • Implement/Evangelize: Third Party Cookie blocking bug 818430, though evolving, will improve control
  • Research: Collusion project improved transparency and generated buzz
  • Research: DNT statistics made available by the web
  • Research: Contextual identity work. (Blushproof, paper)
  • Consult: Cookie Clearinghouse

Build Security into Web Communications