Securing BrowserID

One of the important projects that Mozilla has been building  in 2011 is BrowserID, a user-centric identity protocol and authentication service.  Significant work has gone into building out and testing … Read more

Mozilla at Sheffield Hallam

On Wednesday 14th December, Mark Goodwin from Mozilla’s Infrastructure Security team will be presenting a guest lecture on web and application security at Sheffield Hallam University. The talk explores how … Read more

Automating Test Cases

Earlier this year I wrote about some of the challenges of scaling security efforts in an organization, and I mentioned that we are working to adopt better tooling to assist … Read more

Mozilla Bug Bounty Update

We’re nearly three quarters the way through 2011 and we wanted to provide an update on the progress of the Mozilla bug bounty programs.  The goal of the Mozilla bounty … Read more

Attack against TLS-protected communications

UPDATE 10.18.11: Today, Oracle is releasing a patch update to Java SE to address this vulnerability.  We recommend that users update their Java plugin to ensure that they have the … Read more

Mozilla at OWASP AppSecUSA

Mozilla will be sending several security folks to this year’s OWASP AppSecUSA conference held in Minneapolis, MN on Thursday and Friday (Sept 22, 23).  Stop by and find one of … Read more

DigiNotar Removal Follow Up

Earlier this week we revoked our trust in the DigiNotar certificate authority from all Mozilla software. This is not a temporary suspension, it is a complete removal from our trusted … Read more

Fraudulent *.google.com Certificate

Update (Sept. 6, 2011 @10:37 a.m. PT): New security updates for Firefox are now available. Update (8.30.11 @ 11:25 p.m. PT) Mozilla just released an update to Firefox for Desktop, … Read more