Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

As having personally worked to tell the IE team about a severe bug (crashie.com), I can tell you that their process, community and bureaucracy are by far the worst part of Internet Explorer. You'll get ignored, told that the problem is with your code, mocked in the forums, and then ultimately told the problem isn't a big enough deal (or in my case, too complicated) to fix.

The only way to get the IE team to fix issues is make a public spectacle like Vupen did. And I completely get only exposing bugs when there is a profit to be made, because any other route is counterproductive.



There is a difference between security and non-security bugs. Null pointer dereferences and hangs are not security bugs. Security bugs you are supposed to report to MSRC. Non-security bugs typically has to wait until next version of IE to fix.


That is assuming that it is easy to tell the difference between security and non-security bugs. Null pointer dereferences can and have been exploited to escape security sandboxes. I read about an interesting one a few years in flash. unfortunately all i can find now are secondary sources (http://www.zdnet.com/blog/security/mark-dowds-null-pointer-d...).




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: