Live data from Hacker News

IBM Names Itself Worst Company For Fixing Critical Software Security Bugs

blogs.forbes.com

1–4 of 4 posts

Re: IBM Names Itself Worst Company For Fixing Critical Software Security Bugs

#4

The question is why they don't patch the security holes??

A bug is classified as Critical based on how much access/damage the an attack could create, not based on how it would affect customers. It is possible to have a critical vulnerability that you can expect very few customers to see.