internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Internet Explorer 8

Most Popular Software Downloads
Mozilla Firefox 3.0
Adobe Reader
Ad-Aware 2008 Free
QuickTime for Windows
Internet Explorer 7
Paint Shop Pro
Windows Live Suite
AVG Anti-Virus Free
Opera
CCleaner (Crap Cleaner)

Most Popular Software Articles
Windows Vista Tips & Tricks, Part 1
Windows Vista: Worthy of the Hype?
Windows Wireless Zero Configuration: Five Steps to Sanity


Software Reviews

Mozilla Security: More Than Meets the 'Aye'
Mozilla Responds to Security Process Accusations
Sean Michael Kerner

If open source by definition means that code is open, then why is Mozilla having some of its code discussions behind closed doors?

The reason is simple: to protect users.

Last week security researcher Robert Chapin alleged that Mozilla's security process wasn't open. According to Chapin, certain key discussions surrounding the resolution of security issues with Mozilla Password Manager that he first reported last November were less than entirely open.

Window Snyder, head of security strategy at Mozilla Corp., told internetnews.com that the allegation that Mozilla is not open is not the case. Snyder argued that Mozilla is as open as it can be and even somewhat democratic.

In addition to the publicly available Bugzilla bug database, Mozilla also has a separate security group with membership made up from both Mozilla and the wider community. Currently the group has 86 individual members, with Google, Red Hat, IBM, Sun, Ubuntu and Cenzic among the different groups represented.

"When security issues come in they might be discussed as a bug, but they might also be discussed in the security group," Snyder said. "One of the reasons why we do that is to make sure we get sufficient community feedback on all the different ways we can address a problem and to help us prioritize."

Snyder explained that the password manager bug originally reported by Chapin was discussed publicly in Bugzilla because there was a public disclosure of the vulnerability. Some of the discussion happened on the security group mailing list where some new additional related risks were discussed in a way that wouldn't expose users to additional risk.

"There is a compromise between doing things completely openly and exposing users to additional risk versus doing it with a subset of the population that has been self selected," Snyder said.

The Mozilla Security group is self organizing, Snyder noted. Anyone wanting to join needs to get someone to nominate them and a couple of people to second and third the nomination. Mozilla does that to ensure it has a group that can keep the details of security vulnerabilities within the group until fixes are available.

Chapin has alleged that the Mozilla password manager is not yet fixed. Snyder stated that the bug that Chapin actually first reported is fixed, as Mozilla has already stated in the Firefox 2.0.0.2 release.

That's not to say the Mozilla password manager is bug free.

"There are other bugs that are related that we are prioritizing, and there is at least one that is being fixed in Firefox 2.0.0.3 and other bugs we may fix in the future," Snyder admitted. "Password manager is one of the components that is being considered for a rewrite so a number of issues may be resolved then."

Then there is the issue about the criticality of the password manager bug itself.

The initial bug filed by Chapin was listed in the Bugzilla database as being critical. When Mozilla issued a security advisory on the issue along with the 2.0.0.2 update, it labeled the flaw as being "low impact."

Snyder explained that it's not necessarily a straight line from Bugzilla to security advisory.

"A lot of factors may make a bug critical in Bugzilla, as it includes severity for any bug and not just security," Snyder said. "A security advisory is just about security."

Speaking about security, it's not just the contribution of external researchers that leads to Mozilla security advisories. Mozilla also has an active internal group doing penetration testing against Mozilla products. Snyder noted that they run the whole spectrum of security testing tools and approaches.

"We want to make sure that we're constantly looking for security vulnerabilities because new code is constantly being introduced and threats change," Snyder said.

Mozilla's security effort may also one day lead to a Mozilla open source effort on security tools and information.

"We are looking at ways at making the information we develop as part of our security testing openly available so people can use it to secure large software projects," Snyder said.

The issue of when Mozilla might make such tools and information available is part of the overall balance that Mozilla is striving to seek between functionality, security and disclosure.

"One of the different things about Mozilla is that it's cooperative here and community based," Snyder explained. "What needs to happen is that for each issue that comes up we're considering security in addition to what value this item brings to the user."

News courtesy of internetnews.com

March 16, 2007

Download Mozilla Firefox 2.0!Download

View All Web Browsers

Contents:
1. Mozilla Responds to Security Process Accusations


Additional Articles:

  • Mozilla's Newest FireFox Takes Flight
  • Browser Wars v.2004: Part 1
  • Browser Wars v.2004: Part 2
  • Mozilla Firefox's Volunteer Launch Brigade
  • Rise of the Underdog Browser
  • Firefox Makes It Official
  • Add-ons Extend Firefox Growth
  • Getting the Most Out of Firefox
  • Firefox Thankful for Strong November
  • Firefox, Others at Phishing Risk
  • Browser Wars: Who's Winning, Who's Losing
  • Firefox Torches Competition for Enterprise Linux Award
  • Mozilla Updates Firefox
  • New Firefox Vulnerability Pushes Latest Update
  • Firefox Update Patches Three in Time
  • JavaScript Flaw Hits Mozilla Users
  • Firefox Popularity Spurs Mozilla Traffic Surge
  • Beware the Browser Backlash
  • Another Flaw Found in Mozilla
  • Google Extends Firefox
  • New Firefox Fixes Holes
  • Firefox Advocate Site Hit by Hackers
  • Mozilla Goes for More Green
  • IBM Donates Code to Firefox
  • Firefox Losing Its Grip?
  • Mozilla Under Fire
  • Mozilla FireFox DoS Exploit Code Released
  • Firefox: Nearly a Year Old And Now 100M Strong
  • Happy Birthday, Firefox 1.0
  • Firefox Upgrade Near
  • Firefox at Critical Mass?
  • New Firefox Kills Bugs
  • A Word-Wise Firefox Extension
  • Mozilla Plugs Firefox Bugs
  • FireFox Fixes by the Dozen
  • Goooaaal! Google, Mozilla Kick In Soccer Fix
  • Firefox 2.0: Mozilla's Tabs Overfloweth
  • Firefox 1.5.0.5 Fixes JavaScript Flaws
  • Firefox Is Doing So Well It's Now a Malware Target
  • Firefox 2.0 Beta Tweaking Its Look
  • The Firefox, IE Race to The Finish
  • Firefox Hits Seventh Heaven
  • Firefox 2.0 Release Candidate Goes Live Today
  • Double Deuce as Firefox 2.0 Nears Completion
  • Mozilla Fine-Tunes for Final Release of Firefox 2
  • Firefox 2.0 Released: 'Bon Echo' Lives!
  • Firefox 3.0 Already?
  • Path to Firefox 2.0 Is Cleared
  • Our Phishing Filter Is Better Than Yours!
  • Phishers Lurk for Firefox 2.0 Password Manager
  • Mozilla Fixes Firefox Flaws, Misses One
  • Mozilla Rakes In $53M
  • Mozilla Patches Some Firefox Holes
  • One Flaw and a First for Latest Firefox Update
  • Firefox 1.5 Gets Its Last Update
  • Firefox at Risk Because of Internet Explorer?
  • Firefox Fixes IE Flaws
  • Mozilla Firefox Still at Risk
  • Will Mozilla's Fuzzer Break the Web?
  • Mozilla Updates Firefox Ahead of Black Hat
  • Flaw Still Shadows Firefox
  • Firefox Gets BitTorrent
  • Firefox Gets QuickTime Fix
  • Mozilla Separating Browser from the App
  • Firefox Fixes Cross-Site Flaws
  • Firefox Breaks Web Canvas
  • Warning on Spoofed Login Windows in Firefox
  • Mozilla Update Quashes Slew of Firefox Flaws
  • Firefox Update Tackles Pair of Critical Bugs




  • JupiterOnlineMedia

    internet.comearthweb.comDevx.commediabistro.comGraphics.com

    Search:

    Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

    Jupitermedia Corporate Info


    Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

    Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers