Hacker News new | ask | show | jobs
by true_religion 3418 days ago
The cynical answer would be: try harder Microsoft, and do not let your customers remain vulnerable simply because you can't test two patch-sets at the same time.

If 'trying harder' is not possible due to financial reasons, then the only recourse is disclosure.

This bug will be fixed now, but certainly could have been excluded again because of technical reasons---they're publishing a separate set of patches on SMB again soon, maybe those patches have higher priority to people on the Microsoft org-chart than the patches for this bug.

When companies aren't given hard deadlines for disclosure, they'll just delay forever because there is always a technical reason that you can't do enough testing to satisfy yourself, while doing X, Y, Z which are added to your schedule for political/financial reasons.