On 27/07/12 01:48, Samuel Sidler wrote: > If Mozilla appreciates responsible disclosure, it should definitely > expect the same from its employees. Does a responsible disclosure > policy exist at Mozilla?
This page used to say that we believe in it: http://viewvc.svn.mozilla.org/vc/projects/mozilla.org/trunk/causes/security.html?pathrev=48036&view=diff&r1=48036&r2=47790&diff_format=l but it no longer exists; it must have got removed when we reorganised the "about us" stuff. And it wasn't a policy page anyway. The "Background" section of this document does not use the phrase "responsible disclosure" but I think it commends the idea: http://www.mozilla.org/projects/security/security-bugs-policy.html Of course, it is focussed on us receiving vulnerabilities rather than reporting them. Gerv _______________________________________________ governance mailing list [email protected] https://lists.mozilla.org/listinfo/governance
