<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: 2007-01-18 Trunk builds</title>
	<atom:link href="http://www.squarefree.com/burningedge/2007/01/18/2007-01-18-trunk-builds/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.squarefree.com/burningedge/2007/01/18/2007-01-18-trunk-builds/</link>
	<description>Developments in nightly builds of Mozilla Firefox</description>
	<pubDate>Sat, 05 Jul 2008 11:01:35 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5</generator>
		<item>
		<title>By: Jesse Ruderman</title>
		<link>http://www.squarefree.com/burningedge/2007/01/18/2007-01-18-trunk-builds/#comment-4213</link>
		<dc:creator>Jesse Ruderman</dc:creator>
		<pubDate>Sat, 20 Jan 2007 12:54:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.squarefree.com/burningedge/2007/01/18/2007-01-18-trunk-builds/#comment-4213</guid>
		<description>The idea of creating a "Month of Mozilla Bugs" sounds fun, but I'm guessing we wouldn't want it to work the same way as MoAB (disclosing ~30 severe bugs to the public and the vendor at the same time).  Do you have ideas about how it could work?  Here are some of my thoughts:

* Invite people who might not currently be Mozilla hackers to help fix long-standing bugs (including sg:want bugs); pledge help over IRC and speedy review of patches.

* Discuss some especially clever bug finds (162020), exploits (311497#c10), and bug-finding techniques (349611) that have come from the Mozilla community and independent researchers in the past.  Mention when the bug finders have won bug bounties, and award bug bounties as part of the MoMB if we should have awarded them earlier but forgot to.

Good people to discuss this with include Dan Veditz, Window Snyder, Chris Hofmann, and Mike Schroepfer.

Btw, the first "Month of * bugs" (afaik) was the "Month of Browser Bugs", run by HD Moore in July 2006.</description>
		<content:encoded><![CDATA[<p>The idea of creating a &#8220;Month of Mozilla Bugs&#8221; sounds fun, but I&#8217;m guessing we wouldn&#8217;t want it to work the same way as MoAB (disclosing ~30 severe bugs to the public and the vendor at the same time).  Do you have ideas about how it could work?  Here are some of my thoughts:</p>
<p>* Invite people who might not currently be Mozilla hackers to help fix long-standing bugs (including sg:want bugs); pledge help over IRC and speedy review of patches.</p>
<p>* Discuss some especially clever bug finds (162020), exploits (311497#c10), and bug-finding techniques (349611) that have come from the Mozilla community and independent researchers in the past.  Mention when the bug finders have won bug bounties, and award bug bounties as part of the MoMB if we should have awarded them earlier but forgot to.</p>
<p>Good people to discuss this with include Dan Veditz, Window Snyder, Chris Hofmann, and Mike Schroepfer.</p>
<p>Btw, the first &#8220;Month of * bugs&#8221; (afaik) was the &#8220;Month of Browser Bugs&#8221;, run by HD Moore in July 2006.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Manoj Mehta</title>
		<link>http://www.squarefree.com/burningedge/2007/01/18/2007-01-18-trunk-builds/#comment-4212</link>
		<dc:creator>Manoj Mehta</dc:creator>
		<pubDate>Sat, 20 Jan 2007 08:41:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.squarefree.com/burningedge/2007/01/18/2007-01-18-trunk-builds/#comment-4212</guid>
		<description>Like there has been a MOKB, a MOAB and a Month of Google Bugs, I think the Mozilla org should proactively instate a Month of Mozilla Bugs. If the Mozilla Org announces this initiative before a hacker out there, it will buy positive press, make the organization seem security conscious and will take the limelight away from hackers, among other goals that I can't foresee. Is there anyone I can contact with this idea?</description>
		<content:encoded><![CDATA[<p>Like there has been a MOKB, a MOAB and a Month of Google Bugs, I think the Mozilla org should proactively instate a Month of Mozilla Bugs. If the Mozilla Org announces this initiative before a hacker out there, it will buy positive press, make the organization seem security conscious and will take the limelight away from hackers, among other goals that I can&#8217;t foresee. Is there anyone I can contact with this idea?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
