OCSP Stapling in Firefox

OCSP Stapling has landed in the latest Nightly builds of Firefox! OCSP stapling is a mechanism by which a site can convey certificate revocation information to visitors in a privacy-preserving, … Read more

How to speed up OWASP ZAP scans

So you’ve used OWASP ZAP to scan your web application, and its taking far too long 🙁 Is that it, do you have to lump it or leave it? There … Read more

Responding to Claims of Compromise

Issue A hacking group called “AnonGhost” is claiming they have compromised “Mozilla Emails Managers” and exposed the email address and a 16-character value for 50 accounts. Upon investigation we’ve determined … Read more

Web Developer Security 1.0

Raymond Forbes and I will be presenting Web Developer Security 1.0 on Tuesday, June 18th at 12:15 pm PDT. The training will be held in Mozilla’s Mountain View office and … Read more

Mixed Content Blocking in Firefox Aurora

Firefox 23 moved from Nightly to Aurora this week, bundled with a new browser security feature. The Mixed Content Blocker is enabled by default in Firefox 23 and protects our … Read more

We’re doing a Reddit AMA!

Members of the Mozilla Security community will be participating in an “Ask Me Anything (AMA)” even on Reddit tomorrow, 27-March-2013. We anticipate to run this for 24 hours from March … Read more

Mozilla and Pwn2Own Event

This week the Pwn2Own competition took place as part of the CanSecWest security conference. The Pwn2Own competition provides cash rewards for individuals that are able to demonstrate a security vulnerability … Read more

Using CryptoStick as an HSM

Mozilla maintains a wide range of services which are secured using different solutions.  For internal repositories, our Operations Security team has chosen to use the low-cost, open source and open … Read more