Security/Meetings/SecurityAssurance/2012-09-04

From MozillaWiki
Jump to: navigation, search


« previous week | index | next week »
  • Time: (Weekly) Tuesday at 13:30 PM PDT / 16:30 PM EDT / 21:30 PM UTC.
  • Place: Mozilla HQ, 3A-All Your Base (3rd Floor)
  • Phone (US/Intl): 650 903 0800 x92 Conf: 95316#
  • Phone (Toronto): 416 848 3114 x92 Conf: 95316#
  • Phone (US): 800 707 2533 (pin 369) Conf: 95316#

Agenda

  • ten minute talks - topics with 1 paragraph abstract to pauljt before the next team meeting (sept 11)
    • Submit ideas even if you don't want to give a talk yourself
    • 3-minute lightning talks for the Monday meeting; 10-minute talks grouped into 30-minute brownbags; full brownbags on a single topic
      • Lightning talks with demos advertising brownbags are good too!
  • security conference planning for 2012
    • curtisk
    • psiinon
    • mfuller
    • joes

Security Review Status (koenig)

  • Completed in Q2 2012: 43

https://bugzilla.mozilla.org/buglist.cgi?list_id=4199053;resolution=FIXED;chfieldto=Now;chfield=resolution;query_format=advanced;chfieldfrom=2012-06-30;type0-0-0=anywords;component=Security%20Assurance%3A%20Review%20Request;product=mozilla.org

  • Number of Reviews Completed (so far this quarter): 26 (23)

https://bugzilla.mozilla.org/buglist.cgi?resolution=FIXED;chfieldto=Now;chfield=resolution;query_format=advanced;chfieldfrom=2012-06-30;type0-0-0=anywords;component=Security%20Assurance%3A%20Review%20Request;product=mozilla.org;list_id=4278289

  • Number of Outstanding Reviews: 167 (164)

https://bugzilla.mozilla.org/buglist.cgi?chfieldto=Now;chfield=bug_status;query_format=advanced;bug_status=UNCONFIRMED;bug_status=NEW;bug_status=ASSIGNED;bug_status=REOPENED;component=Security%20Assurance%3A%20Review%20Request;list_id=4278283

Operations Security Update (Joe Stevensen)

Project Updates

Please don't leave blank. Add "No Update" if nothing has changed

Silent updates (rforbes / dveditz)

B2G (Paul Theriault, David Chan)

  • Writing tests for permissions
  • lots of review follow-up ongoing:
   This week PT is working on: navigator.pay, Push API, gaia email client, permissions implementation
  • We will likely need help writing permissions tests. QA is resource constrained.
  • If people want VM (linux with b2g build environement setup) let me know.

Thunderbird (Adam Muntner)

Rust (Jesse Ruderman)

Mobile (Mark Goodwin)

Sync (Simon Bennetts & Adam Muntner)

Services (Simon Bennetts & Adam Muntner)

Social - Pancake (Mark Goodwin)

Jetpack, Add-on SDK, Add-on Builder (Dan Veditz)

JS (Christian Holler)

  • [gkw] Still looking at IonMonkey fuzz results post-workweek-and-PTO

DOM, XPConnect (Jesse Ruderman)

Layout, Style (Jesse Ruderman)

Automation Tools (Gary Kwong)

  • No update

Web Developer Tools (Mark Goodwin)

Networking (Christoph Diehl)

  • No update
  • Working on building the B2G emulator on MacOS 10.8 of which the documentation and dependencies seem to be completely broken/outdated.

Graphics (Christoph Diehl) =

  • No update
  • Bug 760213 blocks font fuzzing on B2G

Networking ( Media / Codecs)

Market (Raymond Forbes)

Firefox APIs (Raymond Forbes)

Payment Flow (Raymond Forbes)

Dynamic API Security Model (Raymond Forbes)

WebRT (Raymond Forbes)

BrowserID

Identity Services (David Chan)

Addons.M.O (Raymond Forbes)

Bugzilla.M.O (Mark Goodwin & Eric Parker)

Mozillians (Raymond Forbes)

MDN (Raymond Forbes)

SUMO (Kitsune) ()