The problem with not doing this is you're just leaving the hole open, and when vendors haven't bothered to respond before the deadline there's very little chance that they will do anything at all if it passes and there's no consequence. If details of the vulnerability are published, the vendor will have to patch it or openly admit they don't care about a significant risk to their business (note that the risk was there all along.)
Sorry, but this is on the vendors. Saying Google shouldn't release details is like saying the public shouldn't be informed of a dangerous flaw in a car model's brake system until the manufacturer has decided whether to launch a new model and what the marketing plan for it should be.
Comments
The problem with not doing this is you're just leaving the hole open, and when vendors haven't bothered to respond before the deadline there's very little chance that they will do anything at all if it passes and there's no consequence. If details of the vulnerability are published, the vendor will have to patch it or openly admit they don't care about a significant risk to their business (note that the risk was there all along.)
Sorry, but this is on the vendors. Saying Google shouldn't release details is like saying the public shouldn't be informed of a dangerous flaw in a car model's brake system until the manufacturer has decided whether to launch a new model and what the marketing plan for it should be.