Articles in “Security”

Revoking Trust in Two TurkTrust Certificates

Update: For clarification, the last sentence of this post references our actions to suspend inclusion of a TURKTRUST root certificate. There are currently two TURKTRUST root certificates included in Mozilla’s … Read more

HTTP Strict Transport Security

The lack of (or inconsistent use of) SSL puts users’ security and privacy at risk. Increasingly, popular sites require SSL not only for operations which are known to directly involve … Read more

Preloading HSTS

HSTS (HTTP Strict Transport Security [1][2]) is a mechanism by which a server can indicate that the browser must use a secure connection when communicating with it. It can be … Read more

Mozilla’s Commitment To Security

October is National Cyber Security Awareness month and we want to take the opportunity to reiterate Mozilla’s security commitment to the Web. From Firefox for Windows, Mac, Linux and Android to … Read more

Click-to-Play Plugins, Blocklist-Style

You may have heard of click-to-play plugins (in short: don’t load plugins until they’re clicked). You may have also heard of the blocklist (essentially a list of addons and plugins … Read more

“Subscription Trap” Websites

“Subscription trap” websites prey on users who are trying to download legitimate free software. These sites trick users into paying for expensive subscriptions for otherwise free software. Some even go … Read more

7 Tips for Fuzzing Firefox More Effectively

In the past half year I learned quite a lot about the different fuzzing approaches that security researchers and contributors use on Firefox. Although information on the subject should be … Read more

Speeding Up Security Reviews

At Mozilla we have a strong commitment to security; unfortunately due to the volume of work underway at Mozilla we sometimes have a bit of a backlog in getting security … Read more