Live data from Hacker News

“Artery chokes after 70 copies of Visual Studio”

connect.microsoft.com

41–50 of 99 posts

Re: “Artery chokes after 70 copies of Visual Studio”

#41
post #28

Not that this is a major bug, but it makes me wonder why a bug report of this detailed nature (basically doing the debugging for Microsoft engineers) shouldn't be eligible for a bounty, just as exposed security flaws are. For this bug, it would be a very small or non-existent bounty since this use case affects almost no one, but what if someone found a major bug that was not a security issue, and worked out the cause…

In my experience the "bounty" is faster attention to the issue from the devs (no-one likes to spend a lot of extra effort on trying to work on something that is vague, ambiguous or confusing), a better chance that a fix is created quickly and addresses your actual issue, and that it creates a good working relationships with the devs for working with them in the future (builds karma). I like to think of it like keeping up my end of the implicit user/Dev contract :)

Re: “Artery chokes after 70 copies of Visual Studio”

#42

Instead, I had to hunt down the person who wrote bugs with only titles and severity level critical....

"unable to reproduce / not enough information" -> close. If users want you to fix a bug, they should assume you're an idiot and can't extrapolate what their problems is from the title alone.

"It depends". If I'm getting this out of a user support case, I can't really do that. The support person in question might get an earful... actually, tense correction, support people have gotten earfuls from me on the virtues of filing the moral equivalent of "it doesn't work"... but for the customer's sake I can't just smash the bug report closed and smile smugly.

Re: “Artery chokes after 70 copies of Visual Studio”

#43
post #2

What I want to know is this, what hellish workflow led to the discovery of this bug?

Maybe it happens if you click on a cs or sln file and then press shift and click somewhere else. This might select all sln or cs files and invoke open on all of them, launching many instances at once. Happened to me once with another programm

Re: “Artery chokes after 70 copies of Visual Studio”

#44
post #32

Earlier quoted context omitted.

Bounties exist for security bugs to make it more profitable to report the bug than it is to exploit it, or to sell knowledge of it to those who would. A buy about opening 70 copies of Visual Studio is unlikely to be very profitable to exploit.

Repectfully, you are incorrect that bounties exist to make it more profitable to disclose than to sell. Corporate bug bounties will never be able to compete with the budgets of nation states. They are basically a way of paying respect for a moral approach to a discovery that takes great skill.

That sounds like wishful thinking to me.

Realistically companies including Microsoft will pay as little as they can to anybody and if they get such nicely detailed bug reports for free why would they ever pay.

Re: “Artery chokes after 70 copies of Visual Studio”

#45

Earlier quoted context omitted.

I do, they are entertaining.

Yes, well... try this one then: http://support.microsoft.com/kb/168702 Entitled "XL97: Data Not Returned from Query Using ORACLE Data Source", one of the solutions reads: Method 2: Move Your Mouse Pointer If you move your mouse pointer continuously while the data is being returned to Microsoft Excel, the query may not fail. Do not stop moving the mouse until all the data has been returned to Microsoft Excel. I'm sure…

In case people think you were being sarcastic (and maybe you were), a large bank used to pay me $10/hour to push F11, F7, F7, F2 for the first 2-3 hours of each day.

Re: “Artery chokes after 70 copies of Visual Studio”

#46
post #32

Earlier quoted context omitted.

Bounties exist for security bugs to make it more profitable to report the bug than it is to exploit it, or to sell knowledge of it to those who would. A buy about opening 70 copies of Visual Studio is unlikely to be very profitable to exploit.

Repectfully, you are incorrect that bounties exist to make it more profitable to disclose than to sell. Corporate bug bounties will never be able to compete with the budgets of nation states. They are basically a way of paying respect for a moral approach to a discovery that takes great skill.

>Corporate bug bounties will never be able to compete with the budgets of nation states.

I somehow first misread that as 'Companies will need budgets of the level of nation states if they start paying for all bugs'.

Re: “Artery chokes after 70 copies of Visual Studio”

#47
post #32

Earlier quoted context omitted.

Bounties exist for security bugs to make it more profitable to report the bug than it is to exploit it, or to sell knowledge of it to those who would. A buy about opening 70 copies of Visual Studio is unlikely to be very profitable to exploit.

Repectfully, you are incorrect that bounties exist to make it more profitable to disclose than to sell. Corporate bug bounties will never be able to compete with the budgets of nation states. They are basically a way of paying respect for a moral approach to a discovery that takes great skill.

Of course they cannot compete on a dollars-for-dollars basis, but people will often accept less return (or pay more) to stay on the up-and-up.

If a criminal would pay you $10 for your exploit, and I would pay you $9 to disclose it- many people would opt to disclose.

Re: “Artery chokes after 70 copies of Visual Studio”

#49
post #29
post #28

Not that this is a major bug, but it makes me wonder why a bug report of this detailed nature (basically doing the debugging for Microsoft engineers) shouldn't be eligible for a bounty, just as exposed security flaws are. For this bug, it would be a very small or non-existent bounty since this use case affects almost no one, but what if someone found a major bug that was not a security issue, and worked out the cause…

The bounty "prize" is you will eventually have a working product to use. If you don't report it, then there is slim chance of the bug being fixed.

> The bounty "prize" is you will eventually have a working product to use.

While an IDE running under Windows is hardly what I would like to work with, a bug that manifests itself only on such extreme circumstances cannot be called a showstopper.

I would worry more about other instances where this Peek() method is being misused like this, perhaps on other situations that happen more frequently than Visual Studio 2013 starts.

As a prize, a Microsoft T-Shirt, a gift card and some public recognition wouldn't hurt. The person who reported this bug did a great job of pinpointing its cause.

Re: “Artery chokes after 70 copies of Visual Studio”

#50

Earlier quoted context omitted.

Repectfully, you are incorrect that bounties exist to make it more profitable to disclose than to sell. Corporate bug bounties will never be able to compete with the budgets of nation states. They are basically a way of paying respect for a moral approach to a discovery that takes great skill.

Of course they cannot compete on a dollars-for-dollars basis, but people will often accept less return (or pay more) to stay on the up-and-up. If a criminal would pay you $10 for your exploit, and I would pay you $9 to disclose it- many people would opt to disclose.

And what if instead of $10 and $9, it's $75,000 and $1,000? And you live in an Eastern European country, where the former will feed your family for years.
Post reply on HN