Incident Reporting Guidance

2019-11-21 Thread Wayne Thayer via dev-security-policy
During the recent CA/Browser Forum meeting, I was asked to provide better guidance on Mozilla's expectations for incident reporting. We're adding a requirement for incident reporting to the new version of our policy [1], but in this message I'm focused on the guidance provided on our wiki [2]. The

Re: Trusted Recursive Resolver Policy in India

2019-11-21 Thread rich.salz--- via dev-security-policy
On Saturday, September 14, 2019 at 7:04:11 AM UTC+8, Wayne Thayer wrote: > Rich: I want to acknowledge your question, which I think is really "what is > the right forum for Mozilla TRR (DNS over HTTPS) policy [1] discussions?" I > don't currently have an answer for you, but will respond when I do.

Re: Trusted Recursive Resolver Policy in India

2019-11-21 Thread Wayne Thayer via dev-security-policy
The only update I can provide at this time is that we're working on it. On Thu, Nov 21, 2019 at 10:08 AM rich.salz--- via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > On Saturday, September 14, 2019 at 7:04:11 AM UTC+8, Wayne Thayer wrote: > > Rich: I want to acknowledge

Re: Incident Reporting Guidance

2019-11-21 Thread Ryan Sleevi via dev-security-policy
On Thu, Nov 21, 2019 at 10:54 AM Wayne Thayer via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > During the recent CA/Browser Forum meeting, I was asked to provide better > guidance on Mozilla's expectations for incident reporting. We're adding a > requirement for incident r