“Artery chokes after 70 copies of Visual Studio”
connect.microsoft.com
connect.microsoft.com
For this bug, it would be a very small or non-existent bounty since this use case affects almost no one, but what if someone found a major bug that was not a security issue, and worked out the cause and fix, as was done in this case? Is that so much less valuable than a security issue?
If you don't report it, then there is slim chance of the bug being fixed.
While an IDE running under Windows is hardly what I would like to work with, a bug that manifests itself only on such extreme circumstances cannot be called a showstopper.
I would worry more about other instances where this Peek() method is being misused like this, perhaps on other situations that happen more frequently than Visual Studio 2013 starts.
As a prize, a Microsoft T-Shirt, a gift card and some public recognition wouldn't hurt. The person who reported this bug did a great job of pinpointing its cause.
I also worked for a startup where we had a handful of users that really went above and beyond reporting bugs. We sent them $25 amazon gift cards as thanks - the feedback was we were being cheap. One of those gift cards has yet to be spent, years later.
This is my point of view and not necessarily right nor wrong.
When the motivation switches from intrinsic (I'm doing this because I'm a good person) to extrinsic (I'm doing this for money) we use a different value of judgment which in this case appears to not have worked as well for you as you would have liked. Instead it may have been better to offer some form of recognition/acclaim to reinforce the intrinsic motivation and promote this behavior. For example helping people on stack overflow rewards you with feeling good about being a productive member of a community; the "reputation" score reinforces that same fact. Now imagine instead of having the reputation score mechanic you were paid 25 cents for every accepted answer instead? Would we have seen the same adoption or would people have not bothered "working" for a few dollars an hour?
Visual Studio is probably the best IDE ever created. Have you even used it?
My problem is not with Visual Studio, but with Windows. After many years using Macs and Linuxes, Windows is an incredibly confusing environment. With Linux and Macs I always know what to expect. Trivial things like setting up wireless networking or a network printer or a multi-monitor setup often involve downloading a program that will install an application that will manage what you want to do. It's insulting to have to download a hundred megabytes of stuff just to use a printer and then have yet another icon somewhere on the screen that doesn't even visually merge with the rest of the environment.
And then you have an environment where you can't even delete an open file. Or eject a USB stick just because some program decided to quit in an unclean way and leave a file open.
After you get used to a consistent and predictable platform, using anything else becomes almost intolerable.
With Windows, it might work somewhat or with great annoyance. Or it might be lovely! Until Windows rot sets in.
IntelliJ is made by the folks that create the resharper plugin that adds decent refactoring to vstudio.
Eclipse has equally good refactoring, -out of the box just as IntelliJ
Of the IDEs I have worked in (Turbo C++ v3.0, Borland C++ v3.1, NetBeans, Eclipse, Rubymine, DrScheme, Turbo Delphi Explorer, RAD Studio XE5, EiffelStudio, GNAT Pro, Visual Studio 6, 2010 and 2013, along with several embedded C environments), Visual Studio is my least favorite. For C++ development on Windows I prefer Eclipse or SublimeText for editing, build using the command line, and debug in WinDbg in order to avoid the awfulness that is the Visual Studio GUI.
Corporate bug bounties will never be able to compete with the budgets of nation states.
They are basically a way of paying respect for a moral approach to a discovery that takes great skill.
Realistically companies including Microsoft will pay as little as they can to anybody and if they get such nicely detailed bug reports for free why would they ever pay.
I thought they only reward major exploit mitigation bypass.
So I am not sure whose argument this supports, but I think ms pays bottom dollar ($0) for general vulns.
I somehow first misread that as 'Companies will need budgets of the level of nation states if they start paying for all bugs'.
If a criminal would pay you $10 for your exploit, and I would pay you $9 to disclose it- many people would opt to disclose.
It would be interesting to know the percentage of people from less-developed countries who choose to claim bounties rather than exploit the bug vs. that of people in more-developed countries. I think you would probably find that fewer bug bounties are claimed by researchers in countries with less computer crime enforcement. I think you would also find that raising the payout for bug bounties would affect that likelihood.
Great thesis project for someone to work on.
I'm imagining that if you phoned up the CIA/NSA to sell them a vulnerability that they would not pay you and instead would send some lawyers to seize the info under a flimsy pretext.
For the most part the gov't acts like working for the gov't is some noble thing worthy of losing pay over, as if it was some special honor to die being paid $40K per year instead of $400K per year.
That said if you can contract something out to the gov't through official channels they'll pay the stupidest rates imaginable. So I guess if there was an FBO contract for vulnerabilities you'd probably do quite well.
If I have to choose between 5 year's wages with a 90% chance of going to jail for a very long time vs. a month's wages as a bounty and a 0% chance of going to jail, I'm going to pick the bounty every time. I think a lot of people would agree with me.
As discussed further down in this thread, raising the value of the payout or lowering the possibility of being caught makes the other side more attractive.
(of course, I would choose to disclose every time, because I'm just a good person.)
Also, besides the crime itself, spending a large sum of ill gotten money without getting caught is a lot easier if you already move in an environment geared for that - few things you can do in a middle class lifestyle that won't arouse suspicion.
1: Once a company got angry and blamed me for delaying their shipping cycle. Another time they laughed when I suggested their memory corruption might be leveraged for escalation. And another vendor told me "buffer overflows would only happen maybe if you had a very fast network IO".
[1] http://www.forbes.com/sites/andygreenberg/2012/03/23/shoppin...
I suppose that's only valuable to criminals. Sorta like saying knowing someone's bank info can let you steal money - no one legit will pay for it.
It's like having another tester on the C# team :)
Source: I was on the visual studio environment team a decade ago, and Rube Goldberg himself could not design a build process that would surprise me, at this point.
Some suck more, some less
And most of the time it's overcomplicated.
I can see 70 files or projects open, but not in VS.
EDIT: Ah, seems I skipped the part where the additional instances are closed.
So I'd say very interweaved if history has its design legacy mantra.
A nitpick but it's really important that HNers understand it: users do not, in fact, pay for bug free products. They pay for products which achieve the benefits promised to them, bugs and all. If they wanted to buy bug-free products, they'd a) make decisions about software adoption driven primarily by externally visible indicia of bug-freeness and b) pay prices similar to that paid by e.g. the Space Shuttle or flight control systems. Users do neither of these things for most software.
If users want you to fix a bug, they should assume you're an idiot and can't extrapolate what their problems is from the title alone.
Do you expect to read interesting bug reports on HN?
http://support.microsoft.com/kb/168702
Entitled "XL97: Data Not Returned from Query Using ORACLE Data Source", one of the solutions reads:
Method 2: Move Your Mouse Pointer
If you move your mouse pointer continuously while the data is being returned to Microsoft Excel, the query may not fail. Do not stop moving the mouse until all the data has been returned to Microsoft Excel.
I'm sure some large bank has employed a data operator to do this at some point. It's a job I guess.
I agree that vs.net is not really pertinent to the core 'hacker' audience here, but this bug report is actually relevant to me, and I didn't get it from my MS-oriented feeds.
I should read HN's FAQ, but aren't articles making it to the front page by being upvoted from new?
what i find much more interesting than this kind of bug though is that there are several possible ways to expose vs bugs with one step after making a new project in the current version...