Security/Meetings/SecurityAssurance/2012-03-27
From MozillaWiki
< Security | Meetings | SecurityAssurance
- Time: (Weekly) Tuesday at 13:30 PM PDT / 16:30 PM EDT / 21:30 PM UTC.
- Place: Mozilla HQ, 3A-All Your Base (3rd Floor)
- Phone (US/Intl): 650 903 0800 x92 Conf: 95316#
- Phone (Toronto): 416 848 3114 x92 Conf: 95316#
- Phone (US): 800 707 2533 (pin 369) Conf: 95316#
Agenda
- Q2 Goals
- https://security.etherpady.mozilla.org/2012-q2-goals
- https://mana.mozilla.org/wiki/display/INFRASEC/2012+-+Q1+Goals
- shared Goals
- OpSec/Releng - Firefox build signing
- Individual Research Goals
- Need team bugzilla keywords for new nomenclature (change over is 9-April)
- csec- dveditz
- wsec- Yvan
- opsec- Joe
Staffing
- michael henry - starting on Monday, April 2
- guillaume (injury; unable to type)
PTO
- curtisk - Starting Thu Afternoon EDT & Friday
- michael - Friday
- mark - Mon-thur (then public hols fri, mon)
- decoder - 2nd half of thur + full friday
- parker - Apr 4-6
- Al- out yesterday and today
Next work week?
- End of summer?
- Week after black hat, to allow combining travel?
Second Half
Project Updates
JS
- [decoder] IonMonkey now being tested on ARM as well (using QEMU), identified 6 bugs already
- [gkw] Found quite a few Valgrind bugs (at least 2) which are being triaged/examined/fixed by Julian Seward
- [fuzzing team] tools refactoring to prepare for eventual open sourcing
- [decoder] Working on script that can auto-reproduce JS bugs from bugzilla, POC available already
B2G
- Lucas driving 2 weeks wrap up of permissions discussion
- SMS review continuing
- Fuzzing SMS ?
- Maybe need to start pushing b2g for secreviews?
Pancake
Preparing for internal only release next week. Testing is a pain..
DevTools
Work week was *awesome* http://www.flickr.com/photos/robceemoz/6860765358/lightbox/ Debugger has some interesting questions (remote debugging)
BrowserQuest
IS LIVE! (and awesome) http://browserquest.mozilla.org/