Not that this is a major bug, but it makes me wonder why a bug report of this detailed nature (basically doing the debugging for Microsoft engineers) shouldn't be eligible for a bounty, just as exposed security flaws are. For this bug, it would be a very small or non-existent bounty since this use case affects almost no one, but what if someone found a major bug that was not a security issue, and worked out the cause…
“Artery chokes after 70 copies of Visual Studio”
41–50 of 99 posts
Re: “Artery chokes after 70 copies of Visual Studio”
#42Instead, I had to hunt down the person who wrote bugs with only titles and severity level critical....
"unable to reproduce / not enough information" -> close. If users want you to fix a bug, they should assume you're an idiot and can't extrapolate what their problems is from the title alone.
Re: “Artery chokes after 70 copies of Visual Studio”
#43What I want to know is this, what hellish workflow led to the discovery of this bug?
Re: “Artery chokes after 70 copies of Visual Studio”
#44Earlier quoted context omitted.
Bounties exist for security bugs to make it more profitable to report the bug than it is to exploit it, or to sell knowledge of it to those who would. A buy about opening 70 copies of Visual Studio is unlikely to be very profitable to exploit.
Repectfully, you are incorrect that bounties exist to make it more profitable to disclose than to sell. Corporate bug bounties will never be able to compete with the budgets of nation states. They are basically a way of paying respect for a moral approach to a discovery that takes great skill.
Realistically companies including Microsoft will pay as little as they can to anybody and if they get such nicely detailed bug reports for free why would they ever pay.
Re: “Artery chokes after 70 copies of Visual Studio”
#45Earlier quoted context omitted.
I do, they are entertaining.
Yes, well... try this one then: http://support.microsoft.com/kb/168702 Entitled "XL97: Data Not Returned from Query Using ORACLE Data Source", one of the solutions reads: Method 2: Move Your Mouse Pointer If you move your mouse pointer continuously while the data is being returned to Microsoft Excel, the query may not fail. Do not stop moving the mouse until all the data has been returned to Microsoft Excel. I'm sure…
Re: “Artery chokes after 70 copies of Visual Studio”
#46Earlier quoted context omitted.
Bounties exist for security bugs to make it more profitable to report the bug than it is to exploit it, or to sell knowledge of it to those who would. A buy about opening 70 copies of Visual Studio is unlikely to be very profitable to exploit.
Repectfully, you are incorrect that bounties exist to make it more profitable to disclose than to sell. Corporate bug bounties will never be able to compete with the budgets of nation states. They are basically a way of paying respect for a moral approach to a discovery that takes great skill.
I somehow first misread that as 'Companies will need budgets of the level of nation states if they start paying for all bugs'.
Re: “Artery chokes after 70 copies of Visual Studio”
#47Earlier quoted context omitted.
Bounties exist for security bugs to make it more profitable to report the bug than it is to exploit it, or to sell knowledge of it to those who would. A buy about opening 70 copies of Visual Studio is unlikely to be very profitable to exploit.
Repectfully, you are incorrect that bounties exist to make it more profitable to disclose than to sell. Corporate bug bounties will never be able to compete with the budgets of nation states. They are basically a way of paying respect for a moral approach to a discovery that takes great skill.
If a criminal would pay you $10 for your exploit, and I would pay you $9 to disclose it- many people would opt to disclose.
Re: “Artery chokes after 70 copies of Visual Studio”
#48Re: “Artery chokes after 70 copies of Visual Studio”
#49Not that this is a major bug, but it makes me wonder why a bug report of this detailed nature (basically doing the debugging for Microsoft engineers) shouldn't be eligible for a bounty, just as exposed security flaws are. For this bug, it would be a very small or non-existent bounty since this use case affects almost no one, but what if someone found a major bug that was not a security issue, and worked out the cause…
The bounty "prize" is you will eventually have a working product to use. If you don't report it, then there is slim chance of the bug being fixed.
While an IDE running under Windows is hardly what I would like to work with, a bug that manifests itself only on such extreme circumstances cannot be called a showstopper.
I would worry more about other instances where this Peek() method is being misused like this, perhaps on other situations that happen more frequently than Visual Studio 2013 starts.
As a prize, a Microsoft T-Shirt, a gift card and some public recognition wouldn't hurt. The person who reported this bug did a great job of pinpointing its cause.
Re: “Artery chokes after 70 copies of Visual Studio”
#50Earlier quoted context omitted.
Repectfully, you are incorrect that bounties exist to make it more profitable to disclose than to sell. Corporate bug bounties will never be able to compete with the budgets of nation states. They are basically a way of paying respect for a moral approach to a discovery that takes great skill.
Of course they cannot compete on a dollars-for-dollars basis, but people will often accept less return (or pay more) to stay on the up-and-up. If a criminal would pay you $10 for your exploit, and I would pay you $9 to disclose it- many people would opt to disclose.