Disappointing. Microsoft has no real argument here, other than perhaps allowing the NSA to use the bug for longer [1]. This is why the NSA has no need for real Windows backdoors. There are plenty of vulnerabilities such as these in Windows that allow privilege escalation or remote execution that are being discovered all the time. All Microsoft has to do is sit back for a few months on them, wait until another one appears, so NSA can start using that one and then fix the old one. "Everyone" wins.
Google gave everyone (only a few big companies actually - everyone else got the "full disclosure" deal) only a week after discovering Heartbleed, and Microsoft is whining about 3 months being too little? Give me a break.
Comments
TheVerge took the same approach:
http://www.theverge.com/2015/1/2/7481069/google-publishes-wi...
Disappointing. Microsoft has no real argument here, other than perhaps allowing the NSA to use the bug for longer [1]. This is why the NSA has no need for real Windows backdoors. There are plenty of vulnerabilities such as these in Windows that allow privilege escalation or remote execution that are being discovered all the time. All Microsoft has to do is sit back for a few months on them, wait until another one appears, so NSA can start using that one and then fix the old one. "Everyone" wins.
Google gave everyone (only a few big companies actually - everyone else got the "full disclosure" deal) only a week after discovering Heartbleed, and Microsoft is whining about 3 months being too little? Give me a break.
[1] http://www.bloomberg.com/news/2013-06-14/u-s-agencies-said-t...