[DIS] Bug Bounty Program

Got something on your mind about the project? This is the correct place for that.


Forum rules

This forum is for feature requests, content changes additions, anything not a Bug in the software.
Please report all bugs on the Support Forums

Post Reply
User avatar
gumi
TMW Adviser
TMW Adviser
Posts: 797
Joined: 19 May 2014, 18:18

[DIS] Bug Bounty Program

Post by gumi »

I'm bad with words so here's the idea: a bug bounty program. We could give rewards for reporting bugs and the reward would depend on bug severity.

Why?
Because we don't have nearly enough testers so most bugs are only found once code hit the main server. Also, some players like to keep bugs to themselves so they can exploit the heck out of it before it gets patched. By giving rewards for reporting bugs we create incentives to test and incentives to not exploit but instead report.

Proposal:
  • Players may report as many bugs as they want and are encouraged to do so, but each individual bug may only be rewarded once. If a player reports a bug that was already reported they get no reward (or maybe a tiny thank you reward).
  • Players must be able to reproduce the bug (preferably on the test server)
  • Official developers with repository access (git push) can not get rewards for reporting bugs (else we could just make up bugs ourselves then report for rewards)
  • Players can not get rewards for bugs they might have reported before the bug bounty program existed
  • Bugs that exist only on the test server and that are caused by WIP code are not eligible for a reward
  • Anyone that is caught exploiting a bug before reporting is not eligible for a reward
  • Rewards will depend on the severity of the bug
Bug classification: (from minor to severe)
  • A - map bugs or other visual bugs
  • B - bugs that prevent from completing/starting a quest or from using some skill/attacks/spells
  • C - bugs that crash the server
  • D - bugs that allow to do a quest again and again, that gives too many items, or that allows to obtain several times the same items
  • E - bugs that consume items (ie a buggy quest that takes your items but gives nothing) or breaks quest state permanently
  • S - bugs that gives GM/Dev/Admin powers (ie @block) or GM/Dev items (ie GM cap)
  • SS - bugs that allows to use someone else's account or characters (or to impersonate them), or that exposes passwords or any non-public account information (ie email)
  • SSS - bugs that gives access to the server, git repos, SQL databases, or any external assets controlled by TMW
Please comment and give your opinion/ideas
User avatar
prsm
TMW Classic
TMW Classic
Posts: 1587
Joined: 24 Mar 2009, 17:18

Re: [DIS] Bug Bounty Program

Post by prsm »

the concept is great, but what are you considering for rewards?
ego is the anesthesia that deadens the pain of stupidity!
User avatar
gumi
TMW Adviser
TMW Adviser
Posts: 797
Joined: 19 May 2014, 18:18

Re: [DIS] Bug Bounty Program

Post by gumi »

prsm wrote:the concept is great, but what are you considering for rewards?
To be honest, I'm not sure, which is why I'm asking players and GMs for input. I'm just a developer and I feel this is not my choice to make, so I'll let the GMs or TMWC handle it and stay out of this
User avatar
wushin
TMW Adviser
TMW Adviser
Posts: 1759
Joined: 18 Dec 2012, 05:56
Location: RiverBest, Brew City, Merica
Contact:

Re: [DIS] Bug Bounty Program

Post by wushin »

Rewarding on a Sliding Scale in relation to bug severity would be ideal.

Make finding bugs on test worth more than finding them once they on live.

Rewards can go to groups for group quest bugs (illia, candors, cindys, etc)

For a minor map bug I'd be fine with giving something like 10 Iron Ore or 5 Terranite Ore or equal value

For something severe like a map crash I'd give a uncommon to a rare depending on how hard the bug was to find and reproduce.

People should be able to "grind & level" with bug reports.
The secret to getting all the important stuff done is doing nothing.
User avatar
Micksha
Lead Developer (SoM)
Lead Developer (SoM)
Posts: 225
Joined: 18 Dec 2015, 15:34

Re: [DIS] Bug Bounty Program

Post by Micksha »

I highly support this idea!
As searching for bugs is easily possible for everyone, and of higher value for the game than getting the rewards by just playing,
I also support Wu-shins Idea of rares for finding crucial bugs (this also would enable to get them for everybody playing this game).
I would like to see this as soon as possible, it will help a lot to avoid our poor bug finding in magic v-3.
You could just set standard reward for simple bugs like Category A,B, interesting items for C,D,E and rares for the S classes.
I would also be fine with the dev team to decide the value of heavier bugs on their own and reward as per their choice.
Thank you.
Post Reply