Mozilla on the expansion for monetary rewards for identifying security issues in the infrastructure elements related to the development of Firefox. The rewards for discovering vulnerabilities on Mozilla's sites and services have doubled, and the bounty for vulnerabilities that could lead to code execution on , has been raised to $15,000.
A reward of $6,000 can be earned for identifying authentication bypass methods and SQL injection, while $5,000 is available for cross-site scripting and CSRF. Key sites include firefox.com/org, mozilla.com/org, addons.mozilla.org, getfirefox.com, bugzilla.mozilla.org, search.services.mozilla.com, archive.mozilla.org, download.mozilla.org
and several dozen other sites related to add-ons, updates, downloads, synchronization, and statistics.
For have bounties approximately half as much. Base sites include observatory.mozilla.org, getpocket.com, premium.firefox.com, hg.mozilla.org, and some internal developer services.
Compared to previously existing conditions, the following key sites and services have been added:
- (digital signature service),
- (automatic code deployment service from
Phabricator into repositories), - (code management tool used for reviewing changes),
- (task execution framework supporting continuous integration and release building processes).
New base sites include:
- (monitor.firefox.com),
- (l10n.mozilla.org),
- The service (wrapper over the Stripe payment system),
- (add-on for traffic protection), Ship It
- Speak To Me
- Additionally, it is possible to
intend to activate in the scheduled January 7 release of Firefox 72 countermeasure methods with annoying requests for granting additional permissions to the website. Many sites abuse the capability in browsers to request permissions, mainly by periodically displaying requests for push notifications. Telemetry analysis showed that 97% of such requests are declined, including 19% of cases where the user immediately closes the page without clicking the accept or decline button. In Firefox 72, such requests will be blocked if there is no recorded interaction from the user with the page (mouse click or key press).
Among the upcoming changes in Firefox 72, it also highlights the background color of the current page for the scroll bar and Public Key Pinning (PKP), which allows the explicit specification of which certificates from Certificate Authorities are permitted for a given website via the Public-Key-Pins HTTP header. This feature is cited as having low demand, risk of compatibility issues (PKP support in Chrome) and the potential to lock oneself out of their own site due to pinning the wrong keys or losing keys (e.g., accidental deletion or compromise due to hacking).
Source: opennet.ru
