{"id":869,"date":"2012-10-31T08:00:31","date_gmt":"2012-10-31T15:00:31","guid":{"rendered":"http:\/\/blog.mozilla.org\/security\/?p=869"},"modified":"2012-10-31T08:36:06","modified_gmt":"2012-10-31T15:36:06","slug":"mozillas-commitment-to-security","status":"publish","type":"post","link":"https:\/\/blog.mozilla.org\/security\/2012\/10\/31\/mozillas-commitment-to-security\/","title":{"rendered":"Mozilla\u2019s Commitment To Security"},"content":{"rendered":"<div id=\"magicdomid396\">October is <a href=\"http:\/\/www.dhs.gov\/national-cyber-security-awareness-month\">National Cyber Security Awareness month<\/a>\u00a0and we want to take the opportunity to reiterate Mozilla\u2019s security commitment to the Web. From Firefox for Windows, Mac, Linux and Android to Firefox OS to the Firefox Marketplace, Persona and more \u2013 Mozilla is committed to delivering secure applications and services that protect our users\u2019 data and privacy. This is more than just a commitment; it\u2019s even in our manifesto.<\/p>\n<\/div>\n<blockquote>\n<div>Individuals&#8217; security on the Internet is fundamental and cannot be treated as optional. <a href=\"http:\/\/www.mozilla.org\/about\/manifesto.html\">http:\/\/www.mozilla.org\/about\/manifesto.html<\/a><\/div>\n<\/blockquote>\n<p><strong><span style=\"text-decoration: underline;\">Open &amp; Transparent<\/span><\/strong><\/p>\n<div>\n<p>In the spirit of Mozilla and our pledge to being open, we report all of our security issues to the public. We don\u2019t just show bugs when someone else publicly discusses an issue or when it is convenient to us; we\u2019re open and transparent as a matter of principle.<\/p>\n<p>When a security issue is present that impacts our users we\u2019ll tell the world what we know, what it means to our users and what we\u2019re\u00a0 doing to address the concern. Our pledge is to provide this information to our users as soon as we know it and fix the issue as quickly and responsibly as possible.<strong><\/strong><\/p>\n<p><strong><span style=\"text-decoration: underline;\">Secure Software Development Lifecycle<\/span><\/strong><br \/>\nLet\u2019s take a quick look at the variety of mechanisms we include within our secure software development lifecycle.<\/p>\n<\/div>\n<ul>\n<li><strong id=\"magicdomid406\">Threat Modeling<\/strong> \u2013 During design we gather security experts, developers and architects to evaluate potential risks of a design and ensure proper security controls are present in the design of the new system or feature.<\/li>\n<li><strong id=\"magicdomid407\">Fuzzing<\/strong> \u2013 Automated scripts and tools send a variety of malformed data into our applications to ensure our products properly handle all sorts of unexpected scenarios that could otherwise lead to vulnerabilities.<\/li>\n<li><strong id=\"magicdomid408\">Security Code Review<\/strong> \u2013 Our security experts and developers manually review critical code to identify the proper use of security controls and proactively find potential flaws.<\/li>\n<li><strong id=\"magicdomid409\">Penetration Testing<\/strong> \u2013 We perform the same actions that a real attacker would take against our applications and ensure all security defenses are properly functioning.<\/li>\n<li><strong>Bug Bounty Program<\/strong> \u2013 Mozilla began the first browser bug bounty program in 2004 and expanded to include critical web applications in 2010.\u00a0 This program builds our larger security community and is another way we proactively discovery security issues and provide fixes long before users are ever at risk.<strong><\/strong><\/li>\n<\/ul>\n<p><strong><span style=\"text-decoration: underline;\">Results?<\/span><\/strong><\/p>\n<p>Our secure software development lifecycle allows us to proactively harden our applications and fix potential security concerns. In fact, since 2010 we\u2019ve only had three public security zero-days (potentially exploitable security vulnerabilities in the current version) within our Firefox code that has caused us to rapidly release a security fix. When these situations arise we deliver fixes to our users in an average of under 48 hours.<\/p>\n<div id=\"magicdomid416\">\n<p><strong><span style=\"text-decoration: underline;\">A Secure Mozilla Experience<\/span><\/strong><\/p>\n<p>Mozilla is committed to the security of our users. We employ a variety of\u00a0 strategies to securely build and maintain our software. When unexpected\u00a0 issues arise, we\u2019re open and honest about what happened and what we\u2019re doing to make it right.\u00a0 We hope that these commitments and our track record speaks to the importance and priority that we place on protecting user data and the web.<\/p>\n<\/div>\n<div id=\"magicdomid417\"><\/div>\n<div>\n<div>Michael Coates<\/div>\n<div>Director of Security Assurance<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>October is National Cyber Security Awareness month\u00a0and we want to take the opportunity to reiterate Mozilla\u2019s security commitment to the Web. From Firefox for Windows, Mac, Linux and Android to &hellip; <a class=\"go\" href=\"https:\/\/blog.mozilla.org\/security\/2012\/10\/31\/mozillas-commitment-to-security\/\">Read more<\/a><\/p>\n","protected":false},"author":1438,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[71,69],"tags":[],"coauthors":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Mozilla\u2019s Commitment To Security - Mozilla Security Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.mozilla.org\/security\/2012\/10\/31\/mozillas-commitment-to-security\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"mozilla\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/2012\/10\/31\/mozillas-commitment-to-security\/\",\"url\":\"https:\/\/blog.mozilla.org\/security\/2012\/10\/31\/mozillas-commitment-to-security\/\",\"name\":\"Mozilla\u2019s Commitment To Security - Mozilla Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/blog.mozilla.org\/security\/#website\"},\"datePublished\":\"2012-10-31T15:00:31+00:00\",\"dateModified\":\"2012-10-31T15:36:06+00:00\",\"author\":{\"@id\":\"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/70ae25c16f09d053c6d8b5eac29dbda9\"},\"breadcrumb\":{\"@id\":\"https:\/\/blog.mozilla.org\/security\/2012\/10\/31\/mozillas-commitment-to-security\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/blog.mozilla.org\/security\/2012\/10\/31\/mozillas-commitment-to-security\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/2012\/10\/31\/mozillas-commitment-to-security\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/blog.mozilla.org\/security\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Mozilla\u2019s Commitment To Security\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/#website\",\"url\":\"https:\/\/blog.mozilla.org\/security\/\",\"name\":\"Mozilla Security Blog\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/blog.mozilla.org\/security\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/70ae25c16f09d053c6d8b5eac29dbda9\",\"name\":\"mozilla\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/image\/98138a294cb6e19a68b02ef8ca9be2dc\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/75d2017e019c87560fe5d148a64659dc?s=96&d=identicon&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/75d2017e019c87560fe5d148a64659dc?s=96&d=identicon&r=g\",\"caption\":\"mozilla\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Mozilla\u2019s Commitment To Security - Mozilla Security Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.mozilla.org\/security\/2012\/10\/31\/mozillas-commitment-to-security\/","twitter_misc":{"Written by":"mozilla","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/blog.mozilla.org\/security\/2012\/10\/31\/mozillas-commitment-to-security\/","url":"https:\/\/blog.mozilla.org\/security\/2012\/10\/31\/mozillas-commitment-to-security\/","name":"Mozilla\u2019s Commitment To Security - Mozilla Security Blog","isPartOf":{"@id":"https:\/\/blog.mozilla.org\/security\/#website"},"datePublished":"2012-10-31T15:00:31+00:00","dateModified":"2012-10-31T15:36:06+00:00","author":{"@id":"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/70ae25c16f09d053c6d8b5eac29dbda9"},"breadcrumb":{"@id":"https:\/\/blog.mozilla.org\/security\/2012\/10\/31\/mozillas-commitment-to-security\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.mozilla.org\/security\/2012\/10\/31\/mozillas-commitment-to-security\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/blog.mozilla.org\/security\/2012\/10\/31\/mozillas-commitment-to-security\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blog.mozilla.org\/security\/"},{"@type":"ListItem","position":2,"name":"Mozilla\u2019s Commitment To Security"}]},{"@type":"WebSite","@id":"https:\/\/blog.mozilla.org\/security\/#website","url":"https:\/\/blog.mozilla.org\/security\/","name":"Mozilla Security Blog","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.mozilla.org\/security\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/70ae25c16f09d053c6d8b5eac29dbda9","name":"mozilla","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/image\/98138a294cb6e19a68b02ef8ca9be2dc","url":"https:\/\/secure.gravatar.com\/avatar\/75d2017e019c87560fe5d148a64659dc?s=96&d=identicon&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/75d2017e019c87560fe5d148a64659dc?s=96&d=identicon&r=g","caption":"mozilla"}}]}},"_links":{"self":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/posts\/869"}],"collection":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/users\/1438"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/comments?post=869"}],"version-history":[{"count":0,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/posts\/869\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/media?parent=869"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/categories?post=869"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/tags?post=869"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/coauthors?post=869"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}