I think the initial principle of the disclosure policy is good, it is intended to put a bit of pressure on bad vendors to fix their bugs. That said I don't think we can classify MS as a bad vendor. They fix lot of critical issues every years, they certainly have their own internal teams working on security issues, they're responsibles.
Vendors with a quite good track record should be allowed to have some slip ups. You cannot compare a vendor who doesn't fix anything on time with one that usually fix issues promptly but occasionally shows a delay on a report. The process should take that into account. I think the binary handling by Google on this one is not very well thought-out.
Comments
I think the initial principle of the disclosure policy is good, it is intended to put a bit of pressure on bad vendors to fix their bugs. That said I don't think we can classify MS as a bad vendor. They fix lot of critical issues every years, they certainly have their own internal teams working on security issues, they're responsibles.
Vendors with a quite good track record should be allowed to have some slip ups. You cannot compare a vendor who doesn't fix anything on time with one that usually fix issues promptly but occasionally shows a delay on a report. The process should take that into account. I think the binary handling by Google on this one is not very well thought-out.