It seems like the response glosses over what Microsoft is actually doing and instead just attacks them for something unrelated (Widows is closed source). In the FSF eyes, Microsoft can do nothing to improve security until Windows is open sourced.
No, I think in the FSF's eyes -- rightfully -- it can't be proven that security has improved. I also can't agree that it isn't related. If I tell you I'm wearing a green shirt, how can you know for sure if you or someone you trust hasn't verified it? You can't. It's the same with MSFT. But in the case of MSFT, it has been proven that they wear a lot of Hypercolor[1] stuff. Is it good that MSFT is doing stuff to make…
I work in a small programming company and we do internal and external audits while maintaining compliancy with federal and state regulators as well as groups like ISO.
Sure, our work is closed source, but that doesn't automatically mean it hasn't been externally verified for a number of different things by a number of different organizations...