Handling of security bugs is flawed

2016-02-10 Thread Rafael Gieschke
I am sorry for having to write this email. I would have preferred Mozilla to fix this internally. I will try to hide any bug details as I still think that there is no use in disclosing these bugs publicly. I have reported two security bugs (1226977, 1226979) in Firefox 80 days ago on November

Re: Handling of security bugs is flawed

2016-02-10 Thread Boris Zbarsky
On 2/10/16 6:08 AM, Rafael Gieschke wrote: I am sorry for having to write this email. Rafael, I'm also sorry you had to write this... There should have been someone watching this component, and I'm sorry there wasn't (largely because the relevant code is not really actively maintained, unfo

Module proposal: telemetry.mozilla.org

2016-02-10 Thread Benjamin Smedberg
I'd like to propose a new module within our governance structure: telemetry.mozilla.org's de facto owner has been Roberto Vitillo for a while now, and I'd like to make that official both for recognition and so that other people know who to talk to about future changes. Name: telemetry.mozilla.

Re: Handling of security bugs is flawed

2016-02-10 Thread Al Billings
We do our best to triage all new security bugs in a timely fashion. These bugs were no exception. They were assigned a sec-moderate rating as they present a limited risk and were added to our bug-fix queue. Mozilla has limited engineering resources, and we use these security ratings to guide which