I think there is something to notice about having a hard fixed timeline for everyone. See from the bug: https://code.google.com/p/google-security-research/issues/de... > Microsoft confirmed that they are on target to provide fixes for these issues in February 2015. They asked if this would cause a problem with the 90 day deadline. Microsoft confirmed that they anticipate to provide fixes for these issues in January 2…
Which sounds like blackmail to me. What did Microsoft have to put aside to move this up in their schedule? Maybe now the release date for Microsoft's new browser slips, giving Google the upper hand? Should corporations force their competitors to move like this? "If you don't drop everything, we're going to release vulnerability details about your product"? I work in information security and patches are important, I u…
If we ask "what gives any company the right to publish vulnerabilities about their competitors?" it's only a short step to asking "what gives journalists the right to publish scathing negative reviews?" The answer is the same: freedom of speech.
It's a fact of life that if you want to fix security bugs, that takes time away from working on other things. If you don't like it, fix the bugs faster, or pay more attention to security from the get-go. Microsoft should be thanking Google for finding the bug in the first place.