[meta] Fission Site Sandboxing Improvements
Categories
(Core :: Security: Process Sandboxing, task)
Tracking
()
Fission Milestone | Future |
People
(Reporter: tjr, Unassigned)
References
(Depends on 6 open bugs, Blocks 1 open bug)
Details
(Keywords: meta)
Reporter | ||
Updated•7 years ago
|
Reporter | ||
Updated•7 years ago
|
Comment 1•5 years ago
|
||
Fission Future because Nika says this doesn't block shipping Fission MVP.
Reporter | ||
Updated•5 years ago
|
Updated•5 years ago
|
Updated•4 years ago
|
Reporter | ||
Updated•4 years ago
|
Updated•3 years ago
|
Comment hidden (obsolete) |
Comment 3•6 months ago
•
|
||
Changing the title to reflect that we have Fission Site Sandboxing, but like all software it's not bug free.
We think the remaining cases here are not concerning enough to be worthy of our (immediate!) attention. But we're keeping this metabug open in case someone finds something serious, so they can be centrally linked.
We consider it security vulnerability if a compromised renderer can do bad things to other sites, and we would consider it for a bug bounty if it's especially bad. If it's stealing browser history or impersonating a Clear-Site-Data request or something like that - it's not a priority, but we'd still link it here to keep track of everything we know we can improve.
Updated•5 months ago
|
Description
•