Re: Firefox Security Team Newsletter Q3 17

2017-11-02 Thread Paul Theriault
For anyone who clicked the link and was confused, NOW the wiki has the latest newsletter. Apologies for that. https://wiki.mozilla.org/SecurityEngineering/Newsletter On Thu, Nov 2, 2017 at 9:26 PM, wrote: > [ See formatted version here: https://wiki.mozilla.org/ > SecurityEngineering/Newsletter

Security Principles for coding secure IPC

2017-10-30 Thread Paul Theriault
m and others for their input and review. Feedback, corrections, suggestions all welcome. Regards, Paul Theriault Firefox Security Assurance ___ dev-platform mailing list dev-platform@lists.mozilla.org https://lists.mozilla.org/listinfo/dev-platform

Firefox Security Team Newsletter Q2 2017

2017-08-08 Thread Paul Theriault
I posted this to dev-security already, but received suggestions to bring our newsletter to dev-platform as well. I believe this list is plaintext, so instead of pasting broken content, I'll encourage you to read the online version here: https://wiki.mozilla.org/SecurityEngineering/Newsletter Or be

Hardening the Firefox Sandbox

2016-12-01 Thread Paul Theriault
Hi all, Security Engineering has started a project to harden Firefox against attack in a post-sandboxed world. It’s early days yet for sandboxing, but conscious of the work required, I wanted to raise sandboxing as a topic for discussion, and request input towards developing a sandbox security

Re: Enabling seccomp-bpf for content process on nightly Linux desktop

2016-07-05 Thread Paul Theriault
> On 6 Jul 2016, at 3:39 AM, Steve Fink wrote: > > On 07/05/2016 01:33 AM, Julian Hector wrote: >> If you encounter a crash that may be due to seccomp, please file a bug in >> bugzilla and block Bug 1280415, we use it to track issues experienced on >> nightly. > > What would such a crash look l