Security Landing

From MozillaWiki
Revision as of 22:17, 26 June 2014 by Sidstamm (talk | contribs) (Created page with "__NOTOC__ “Individuals’ security and privacy on the Internet are fundamental and must not be treated as optional.” - [http://www.mozilla.org/en-US/about/manifesto/...")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to navigation Jump to search
“Individuals’ security and privacy on the Internet are 
fundamental and must not be treated as optional.”
  - Mozilla Manifesto Principle 4

The Mozilla Security community provides leadership in security by building security features, testing software and systems, and leading industry standards to ensure that individuals retain the ability to make meaningful choices about security and privacy on the Internet.

This page documents the security-related activities where Mozilla active, and how to join us.

Many Efforts

To create a comprehensive security cover, we approach security and privacy from many angles at Mozilla.

Operations Security
Network/System Security, Incident detection and response, infrastructure policy development and compliance.
Security Engineering
Making the web platform more secure! Web security feature development (CSP, HSTS, SSL) and gecko security heavy lifting (Firefox plumbing).
Firefox OS Security
Ensure Firefox OS security throughout OS development lifecycle, make Apps safe and secure, respond to vulnerability and 0day reports on Firefox OS, work with partners to extend our security principles to wherever the Firefox OS brand is employed.
Fuzzing
We throw random data at a program until something goes wrong, causing faults which are often security related.
Web Services Security
...

How to Get Involved!

Find Us:

  • security@mozilla.org - email us any questions, concerns, etc
  • Bugzilla Keyword - sec-review-needed - We look for where our input is needed based on this bugzilla keyword and will jump in to provide assistance
  • #security on IRC
  • File a security/privacy review request via this link
  • Attend a Security Talk given by one of the security team
  • Join the dev-security newsgroup or mailing list

Follow our work:

Contribute: Wanna pitch in, maybe do a project? Check out SecurityEngineering/Projects or the good first bugs list and if one interests you, contact us!