For me, one interesting aspect of this vulnerability and mitigation is how it illustrated the hierarchy of the Drupal community.

The Acquia blog post about this [1] is up-front with the fact that major companies who participate in the Drupal Security Team had a 7-day lead time on everyone else for this vulnerability. 7 days! Everyone else learned about it at the same time the bad guys did, and it turns out they had about 7 hours before attacks came flooding in. [2]

Particularly for folks in Europe, this was potentially disastrous, because the vulnerability and patch were released at about 10pm their time.

The Acquia blog post concludes by thanking the "all-volunteer Drupal Security Team." But the reward for participation is obvious: advance warning. If I ran a big Drupal shop, I would direct one of my engineers to spend time on, and try to join, the Drupal Security Team. It's just good insurance.

I am a Drupal user, and I have made sure that we are doing business with at least one of those companies, for the same reason. I was warned on Tuesday that a critical patch was coming on Wednesday; we were ready to go and patched everything within an hour of release.

Does that seem fair? I have to think that there is a better way to release these sorts of critical patches. I can't think of any reason the Security Team could not have posted a public announcement on Monday or Tuesday saying "get ready--critical patch coming Wednesday." Instead we got a PSA 2 weeks afterward, telling people that they should have been faster.

[1] https://www.acquia.com/blog/shields

[2] https://www.drupal.org/PSA-2014-003