Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Find a Bug? Don't E-Mail Microsoft
Brian McWilliams, SecurityFocus 2002-07-23

It may be the most-used vendor bug reporting address in history. This week Redmond put "secure@microsoft.com" out to pasture in favor of a handy Web form.

Comments Mode:
Find a Bug? Don't E-Mail Microsoft 2002-07-23
Anonymous (1 replies)
Ridiculous. Just makes it easier for them to pretend they never received any reports [read: delay!)]

What's the matter with the email method. Their server can't handle the daily flood of reports :->...

[ more ]  [ reply ]
Find a Bug? Don't E-Mail Microsoft 2002-07-24
Anonymous
It sounds like they were getting a lot of incomplete reports via the email method. (Which is still available, BTW.) This is just a way to coach people to include the necessary info.

...

[ more ]  [ reply ]
Poor Idea, baby goes out with the bathwater... 2002-07-23
Geoff Shively
I believe this is a really bad idea on Microsoft's part. My company PivX Solutions has emailed Microsoft 2 times prior to releasing large vulnerabilities, or even just to help them correct an error in their work around; but we never seem to receive a reply.

Our policy is to notify the vendor, in ...

[ more ]  [ reply ]
Two reporting routes are better than one. 2002-07-24
Avro (1 replies)
There is an large advantages to this form for both micorsoft and the security comunity in that this form requires some basic infomation and most importantly an decription of how to reproduce this attack. With out this infomation the form can not be sent meaning that the number of incompleet discript...

[ more ]  [ reply ]
Two reporting routes are better than one. 2002-07-24
Johan Denoyer
I have had to contact Microsoft concerning some bugs... I used both methods, and I received an answer with-in half a day for both of them. I guess the webform is used to collect data they need by asking questions. Could be used for non-experts. (Yes newbees sometimes find security flaws)...

[ more ]  [ reply ]
Don't E-Mail Microsoft--they dont care!!! 2002-07-24
technicolour yawn (1 replies)
Why bother alerting MS to the gaping flaws in their code?

First, they dont care.

Second, you're going to release the alert to the appropriate mailing lists shortly thereafter anyway.

Third, why are you using MS products in the first place, dont you know better ??

Fourth, They dont care (unless t...

[ more ]  [ reply ]
Re: Don't E-Mail Microsoft--they dont care!!! 2009-07-06
Ben
Microsoft does care about flaws that its users find. I'm pretty sure that humans in Redmond *do* read each and every submission.

By notifying Microsoft about a security problem you find, rather than immediately posting it to your favorite mailing list, you could be indirectly helping millions of ...

[ more ]  [ reply ]
Hmmmmm 2002-07-24
Anonymous Coward from dk
The new report form dosn't work with Opera 6!!...

[ more ]  [ reply ]
Paper trail... 2002-07-24
Michel Salim <salimma1NOatSPAMyahoo.co.uk
Surely there should be an option, as in Bugzilla (used by Mozilla, Red Hat etc) to Cc the sender the bug report?

I take it the information is converted to an e-mail anyway.

- Michel...

[ more ]  [ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus