On 27/07/12 01:48, Samuel Sidler wrote:
> If Mozilla appreciates responsible disclosure, it should definitely
> expect the same from its employees. Does a responsible disclosure
> policy exist at Mozilla?

This page used to say that we believe in it:

http://viewvc.svn.mozilla.org/vc/projects/mozilla.org/trunk/causes/security.html?pathrev=48036&view=diff&r1=48036&r2=47790&diff_format=l

but it no longer exists; it must have got removed when we reorganised
the "about us" stuff. And it wasn't a policy page anyway.

The "Background" section of this document does not use the phrase
"responsible disclosure" but I think it commends the idea:
http://www.mozilla.org/projects/security/security-bugs-policy.html

Of course, it is focussed on us receiving vulnerabilities rather than
reporting them.

Gerv


_______________________________________________
governance mailing list
[email protected]
https://lists.mozilla.org/listinfo/governance

Reply via email to