|
Diese Diskussion wurde archiviert.
Es können keine neuen Kommentare abgegeben werden.
|
 |
|
 |
 |
Von Anonymer Feigling am Friday 20. May 2005, 08:13 MEW (#1)
|
|
 |
 |
 |
Der Vortrag finded nicht am Donnerstag, sondern am Dienstag (24.05.2005) statt..
Topic: Technologies and Techniques for Security in the
Mozilla Project
Speaker: Mike Shaver, Mozilla Foundation
Place: ETH Zurich, HG F 5 (main building, floor F, room 5)
Date: Tuesday, May 24, 2005
Time: 17:15 - 18:15 h
Abstract:
The Mozilla Project, led by the Mozilla Foundation, develops the
Firefox web browser and Thunderbird email client for a user base 50
million strong and growing. In order to protect those users, Mozilla
employs a wide range of techniques and technologies to improve the
robustness of its data handling, inform users about possibly-dangerous
actions, and encourage wide-spread attention to security issues in the
Mozilla codebase. In addition to the concerns over buffer overflow and
heap-abuse attack that are shared by virtually all developers
concerned with possibly-hostile data, the web-like application model
requires that interactions between trusted application "chrome" and
untrusted web "content" be handled carefully. These issues of
content-isolation have proven to be central to the security of Mozilla
applications, as with most Internet-facing software, and we will
present an overview, historical and forward-looking, of the challenges
we have faced in securing this unusual border, as well as techniques
used to overcome those challenges.
While technical security issues are certainly a significant aspect of
Mozilla software development, there are also a number of additional
challenges and opportunities that arise from the open source
development model employed. A presentation of this organizational
context will include discussion of source auditing; the Mozilla "bug
bounty" programme; update, notification, and disclosure; and helping
developers produce extensions that preserve the security model of
their host applications. Our coverage of Mozilla security issues will
conclude with an overview of future directions in enhancing the
security of the Mozilla platform, applications and project management.
|
|
 |
 |
|
 |
|
 |
 |
|
 |
 |
 |
Wird der Vortrag wie damals bei RMS als ogg-File zum downloaden sein? Das find ich nämlich sehr praktisch - vorallem auch für die, die halt nicht am Vortrag sein können. --
Völker hört die Signale...
|
|
 |
 |
|
|
|
 |
|
 |
 |
|
 |
 |
 |
Ich glaube nicht, die Vortraege werden ja nichtmal aufgezeichnet..
|
|
 |
 |
|
 |
|
 |
 |
|
 |
 |
 |
für unkundige des eth hg's:
plan
|
|
 |
 |
|
 |
|
 |
 |
Von Anonymer Feigling am Sunday 22. May 2005, 00:20 MEW (#5)
|
|
 |
 |
 |
|
 |
 |
|
 |
|
 |
 |
Von Anonymer Feigling am Sunday 22. May 2005, 23:55 MEW (#6)
|
|
 |
 |
 |
Da muss doch was zu machen sein :D
|
|
 |
 |
|
|