ResidentGeek wrote:
As someone who did test for Microsoft for a long time and still works in the QA industry, don't assume that a professional tester didn't find it. I'd be surprised if basic injection wasn't tested - it was a large segment of test when I worked in Microsoft.com's test organization several years ago, and I doubt it's any different over at MSDN.
Things are worse than I imagined.
ResidentGeek wrote:
just because the test organization found the issue doesn't mean that it was decided to fix it.
WOW :wtf:
ResidentGeek wrote:
Just wanted to speak up for those who may not be at fault here.
I am sorry for assuming that the testers didn’t find the vulnerability. I wasn’t aware of the work environment. This is really worse than I could have imagined.
ResidentGeek wrote:
Test in many companies (and in some, but not all divisions at Microsoft) is often considered an advisory capacity, but the decision about the priority of the bug may actually be determined by the business folks.
Again I have to say WOW :omg:
ResidentGeek wrote:
That's a horrible place for it to happen, since often the business team doesn't have the expertise to make that determination, but the business folks DO hold the purse strings
Perhaps this is an argument for product liability in the software industry. If the cost of releasing a defective product was considerable there would be a different cost/benefit equation.
ResidentGeek wrote:
And, to be fair, it could be that for some reason it would have been very costly or counter-productive to fix it, or there may have been some reason why they chose to allow it.
How could it be counter-productive to fix an injection vulnerability. You are not being fair, you are being apologetic for people who are not treating others fairly.
ResidentGeek wrote:
I saw all of those scenarios at one time or another, at one company or another. I'm not saying I agree with that, just pointing out that it's not fair to imply that the testers were at fault, necessarily.
I feel sorry that you had to work under those c