HZGN.COM
welcome to my space
X
Welcome to:hzgn.com
Search:  
NAVIGATION: Home >>
Mozilla Security: More Than Meets The 'Aye'
Published by: mike 2008-11-18

TheMusic.LT Nemokama MP3 muzika::
Dawn Tallman - Work It Out (Ruff & Tort Meets DJ Disciple Remix) (7:16) Natalie Broomes - Nothing Better Than Your Lovin (Roog and Prom Remix)
http://www.themusic.lt/profile.php?lookup=11474
HOME
If open source by definition means that code is open, then why is Mozilla having some of its code discussions behind closed doors?

The reason is simple: to protect users.

Last week security researcher Robert Chapin alleged that Mozilla's security process wasn't open. According to Chapin, certain key discussions surrounding the resolution of security issues with Mozilla Password Manager that he first reported last November were less than entirely open.

MySpace.com - rachel - 16 - Female - central coast, AU - www ::
more than anything else i wanto learn another language. .. lol yeah aye i think im gunna be working fridays once netball is finished.
http://profile.myspace.com/index.cfm?fuseaction=user.viewprofile&friendid=118757264
HOME
Window Snyder, head of security strategy at Mozilla Corp., told internetnews.com that the allegation that Mozilla is not open is not the case. Snyder argued that Mozilla is as open as it can be and even somewhat democratic.

In addition to the publicly available Bugzilla bug database, Mozilla also has a separate security group with membership made up from both Mozilla and the wider community. Currently the group has 86 individual members, with Google, Red Hat, IBM, Sun, Ubuntu and Cenzic among the different groups represented.

"When security issues come in they might be discussed as a bug, but they might also be discussed in the security group," Snyder said. "One of the reasons why we do that is to make sure we get sufficient community feedback on all the different ways we can address a problem and to help us prioritize."

Snyder explained that the password manager bug originally reported by Chapin was discussed publicly in Bugzilla because there was a public disclosure of the vulnerability. Some of the discussion happened on the security group mailing list where some new additional related risks were discussed in a way that wouldn't expose users to additional risk.

Kaspersky Internet Security 8.0.0.89 Beta - 9Down.COM::
Jan 1, 2008 Heheheh, who has more of a mental disability than the guy who believes .. Well, Anti-Brain these tests are fun to giggle at aye, retard?
http://www.9down.com/Kaspersky-Internet-Security-8-0-0-89-Beta-20182/
HOME
"There is a compromise between doing things completely openly and exposing users to additional risk versus doing it with a subset of the population that has been self selected," Snyder said.

The Mozilla Security group is self organizing, Snyder noted. Anyone wanting to join needs to get someone to nominate them and a couple of people to second and third the nomination. Mozilla does that to ensure it has a group that can keep the details of security vulnerabilities within the group until fixes are available.

Chapin has alleged that the Mozilla password manager is not yet fixed. Snyder stated that the bug that Chapin actually first reported is fixed, as Mozilla has already stated in the Firefox 2.0.0.2 release.

2005 C16 mm Myanmar 147-149::
File Format: PDF/Adobe Acrobatdevelopment of the telephone network to meet the needs of. the people. more than 1000 corporate users in the country and also hosts
http://www.digital-review.org/2005-6PDFs/2005%20C16%20mm%20Myanmar%20147-149.pdf
HOME
That's not to say the Mozilla password manager is bug free.

"There are other bugs that are related that we are prioritizing, and there is at least one that is being fixed in 2.0.0.3 and other bugs we may fix in the future," Snyder admitted. "Password manager is one of the components that is being considered for a rewrite so a number of issues may be resolved then."

Then there is the issue about the criticality of the password manager bug itself.

The initial bug filed by Chapin was listed in the Bugzilla database as being critical. When Mozilla issued a security advisory on the issue along with the 2.0.0.2 update, it labeled the flaw as being "low impact."

Snyder explained that it's not necessarily a straight line from Bugzilla to security advisory.

"A lot of factors may make a bug critical in Bugzilla, as it includes severity for any bug and not just security," Snyder said. "A security advisory is just about security."

Speaking about security, it's not just the contribution of external researchers that leads to Mozilla security advisories. Mozilla also has an active internal group doing penetration testing against Mozilla products. Snyder noted that they run the whole spectrum of security testing tools and approaches.

"We want to make sure that we're constantly looking for security vulnerabilities because new code is constantly being introduced and threats change," Snyder said.

Mozilla's security effort may also one day lead to a Mozilla open source effort on security tools and information.

"We are looking at ways at making the information we develop as part of our security testing openly available so people can use it to secure large software projects," Snyder said.

The issue of when Mozilla might make such tools and information available is part of the overall balance that Mozilla is striving to seek between functionality, security and disclosure.

"One of the different things about Mozilla is that it's cooperative here and community based," Snyder explained. "What needs to happen is that for each issue that comes up we're considering security in addition to what value this item brings to the user."


Red Hat: RHEL 5 Just the Beginning
ReactOS on The Windows Tail

PRINT Add to favorites
  • is there a totally wireless fax machine available or do they all have to be connected to a landline
  • where to search for wireless driver c794wu laptop
  • i need to know how to make natural highlights
  • i have an hp laptop out of warranty
  • i 039 v just washed my hair with conditioner and shampoo and now it curly what can i do to leave it curly
  • what are some unique pretty names
  • in the shower do you face towards the water or away from it
  • will i be able to transfer data from my pc to my laptop using a cord
  • first kiss 1963
  • vista won 039 t start up
  • holocaust didn 039 t happen
  • the she hair straightener
  • what do you know abo
  • destination downgrad
  • ipod wedding ceremony music help
  • fashion show attire what should i wear
  • was michael the archangel the one responsible for throwing satan into
  • mexican survival tip

  • what is that website that can tell you exactly what you 039 re doing and everything
  • christians can you say bible have no mistakes contradictions unscie… statements
  • how much would it cost
  • when your mind wanders what do you find yourself contemplating
  • wine tasting in youn
  • optimum online download speed 14500kb s normal but the upload speed is so slow i dont even get a result
  • why can 039 t i stop thinking about my toenails
  • what things should be kept in mind before buying a laptop
  • which laptop to buy 13 or 15
  • i am running vista home premium and when i turned on my computer my taskbar was a light gray
  • would you prefer a common or uncommon name
  • secured loans – an
  • is this normal for any hair types
  • what type of disc should i use
  • can you create new prime colors for the rainbow
  • unlimited wireless broadband in western australia particularly perth
  • seventh sense
  • physical memory issue
  • #If you have any other info about this subject , Please add it free.#
    Your name:
    E-mail:
    Telphone:

    Your comments:


    If you have any other info about Mozilla Security: More Than Meets The 'Aye' , Please add it free.
    About us |Contact us |Advertisement |Site map |Exchange links
    Copyright© 2008hzgn.com All Rights Reserved