{"id":666,"date":"2012-03-16T13:18:28","date_gmt":"2012-03-16T20:18:28","guid":{"rendered":"http:\/\/blog.mozilla.org\/security\/?p=666"},"modified":"2012-03-16T13:18:28","modified_gmt":"2012-03-16T20:18:28","slug":"make-things-better","status":"publish","type":"post","link":"https:\/\/blog.mozilla.org\/security\/2012\/03\/16\/make-things-better\/","title":{"rendered":"Make Things Better (or, how I learned to stop worrying and love security again)"},"content":{"rendered":"<p>Working in application security can be frustrating. Often you&#8217;re working around problems in software you have little control over, making ugly bandaids that must stay in place until a vendor wakes up to an issue.<\/p>\n<p>Perhaps this is why security folk, as a community, have gotten into the habit of complaining about how things are broken and leaving it there; how often have you attended a presentation where a vendor is criticised for making a mistake, but no solution is suggested, or help offered?<\/p>\n<p>This frustration is one of the reasons I was really excited about coming to Mozilla. &#8220;Finally! I can make a difference!&#8221;, I thought. It didn&#8217;t take long for me to realise I&#8217;d missed something important; there was nothing stopping me before. You don&#8217;t need to be a Mozilla employee to contribute.<\/p>\n<p>Why?<\/p>\n<p>Because Mozilla is open. Not &#8216;open&#8217; as in &#8220;here&#8217;s this neat thing we built behind closed doors (and here&#8217;s the source)&#8221;, rather, the kind of open that allows anyone with good ideas and talent to make a difference. We develop everything in the open so you can contribute ideas, patches and security guidance too.<\/p>\n<p>I didn&#8217;t realise that I could contribute in all of these ways; had it occurred to me, some of the things I&#8217;m working on now could have been in the browser I used years ago. Has it occurred to you?<\/p>\n<p>So what can you do?<\/p>\n<ul>\n<li>Get involved in security reviews (<a href=\"https:\/\/wiki.mozilla.org\/Security\/Reviews\/\">wiki page<\/a>, <a href=\"https:\/\/mail.mozilla.com\/home\/ckoenig@mozilla.com\/Security%20Review.html\">calendar<\/a>)<\/li>\n<li>Join discussions on mailing lists (<a href=\"https:\/\/lists.mozilla.org\/listinfo\">mailing lists<\/a>, <a href=\"http:\/\/groups.google.com\/groups\/dir?sel=usenet%3Dmozilla\">Google Groups<\/a>)<\/li>\n<li>Participate in our <a href=\"http:\/\/www.mozilla.org\/security\/bug-bounty.html\">bug bounty program<\/a><\/li>\n<\/ul>\n<p>We&#8217;re going to be giving some additional ideas of areas where you can get involved over the coming weeks; watch this space!<\/p>\n<p>&#8212; Mark Goodwin<br \/>\nTwitter: @mr_goodwin<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Working in application security can be frustrating. Often you&#8217;re working around problems in software you have little control over, making ugly bandaids that must stay in place until a vendor &hellip; <a class=\"go\" href=\"https:\/\/blog.mozilla.org\/security\/2012\/03\/16\/make-things-better\/\">Read more<\/a><\/p>\n","protected":false},"author":401,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[69],"tags":[],"coauthors":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Make Things Better (or, how I learned to stop worrying and love security again) - Mozilla Security Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.mozilla.org\/security\/2012\/03\/16\/make-things-better\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Mark Goodwin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/2012\/03\/16\/make-things-better\/\",\"url\":\"https:\/\/blog.mozilla.org\/security\/2012\/03\/16\/make-things-better\/\",\"name\":\"Make Things Better (or, how I learned to stop worrying and love security again) - Mozilla Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/blog.mozilla.org\/security\/#website\"},\"datePublished\":\"2012-03-16T20:18:28+00:00\",\"dateModified\":\"2012-03-16T20:18:28+00:00\",\"author\":{\"@id\":\"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/f8cd6cae5862d9db51300db343c769c9\"},\"breadcrumb\":{\"@id\":\"https:\/\/blog.mozilla.org\/security\/2012\/03\/16\/make-things-better\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/blog.mozilla.org\/security\/2012\/03\/16\/make-things-better\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/2012\/03\/16\/make-things-better\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/blog.mozilla.org\/security\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Make Things Better (or, how I learned to stop worrying and love security again)\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/#website\",\"url\":\"https:\/\/blog.mozilla.org\/security\/\",\"name\":\"Mozilla Security Blog\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/blog.mozilla.org\/security\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/f8cd6cae5862d9db51300db343c769c9\",\"name\":\"Mark Goodwin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/image\/0987c099d8ff38099c0d4aece7c3f0a5\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/01f288b6d43bba75d08b107c50222350?s=96&d=identicon&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/01f288b6d43bba75d08b107c50222350?s=96&d=identicon&r=g\",\"caption\":\"Mark Goodwin\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Make Things Better (or, how I learned to stop worrying and love security again) - Mozilla Security Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.mozilla.org\/security\/2012\/03\/16\/make-things-better\/","twitter_misc":{"Written by":"Mark Goodwin","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/blog.mozilla.org\/security\/2012\/03\/16\/make-things-better\/","url":"https:\/\/blog.mozilla.org\/security\/2012\/03\/16\/make-things-better\/","name":"Make Things Better (or, how I learned to stop worrying and love security again) - Mozilla Security Blog","isPartOf":{"@id":"https:\/\/blog.mozilla.org\/security\/#website"},"datePublished":"2012-03-16T20:18:28+00:00","dateModified":"2012-03-16T20:18:28+00:00","author":{"@id":"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/f8cd6cae5862d9db51300db343c769c9"},"breadcrumb":{"@id":"https:\/\/blog.mozilla.org\/security\/2012\/03\/16\/make-things-better\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.mozilla.org\/security\/2012\/03\/16\/make-things-better\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/blog.mozilla.org\/security\/2012\/03\/16\/make-things-better\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blog.mozilla.org\/security\/"},{"@type":"ListItem","position":2,"name":"Make Things Better (or, how I learned to stop worrying and love security again)"}]},{"@type":"WebSite","@id":"https:\/\/blog.mozilla.org\/security\/#website","url":"https:\/\/blog.mozilla.org\/security\/","name":"Mozilla Security Blog","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.mozilla.org\/security\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/f8cd6cae5862d9db51300db343c769c9","name":"Mark Goodwin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/image\/0987c099d8ff38099c0d4aece7c3f0a5","url":"https:\/\/secure.gravatar.com\/avatar\/01f288b6d43bba75d08b107c50222350?s=96&d=identicon&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/01f288b6d43bba75d08b107c50222350?s=96&d=identicon&r=g","caption":"Mark Goodwin"}}]}},"_links":{"self":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/posts\/666"}],"collection":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/users\/401"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/comments?post=666"}],"version-history":[{"count":0,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/posts\/666\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/media?parent=666"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/categories?post=666"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/tags?post=666"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/coauthors?post=666"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}