Главная
Study mode:
on
1
Intro
2
Agenda
3
What is Mozilla
4
Open Source Threat Model
5
Remediation
6
Web Services
7
Threat Model
8
Bug Bounty
9
Economics of Zero Day Bugs
10
Active programs
11
Open source
12
Open source vs proprietary
13
Mozillas open source projects
14
Bug bounty program
15
Internal communication
16
Web bug intake
17
Mozilla Firefox
18
Chris Hoffman
19
Statistics
20
Bounty Hunters
21
Measuring Security
22
Too Many Variables
23
Which is Safer
24
What do we learn
25
What can we actually measure
26
What security is
27
How much can we know
28
Garbage in garbage out
29
Qualitative assessments
30
epistemological problem
31
security verification
32
hard to measure
33
maturity model
34
selfdelusion
35
Road Map
36
Red Team
37
Summary
Description:
Explore open source approaches to application and service security in this conference talk from AppSecEU 2016 in Rome. Delve into Mozilla's open source threat model, bug bounty program, and web services security strategies. Learn about the economics of zero-day bugs, internal communication processes, and web bug intake methods. Examine the challenges of measuring security, including the limitations of quantitative assessments and the epistemological problems associated with security verification. Gain insights into qualitative assessments, maturity models, and the complexities of determining which security approaches are most effective. Discover Mozilla's road map for improving security and the role of red team exercises in enhancing overall security posture.

Open Source Approaches to Security for Applications and Services - Mozilla Case Study

OWASP Foundation
Add to list
0:00 / 0:00