I'm considering migrating away from Microsoft products because of this; they offer bounties for important bugs but the way they handle reports is horrible.
I'm considering migrating away from Microsoft products because of this; they offer bounties for important bugs but the way they handle reports is horrible.
I suggest you take the long view and compare how Microsoft handled security disclosures in the past ("That vulnerability is entirely theoretical.") compared with today (inviting hackers to their oncampus Bluehat conference, sponsoring CanSecWest, etc). Things could always get better, but they've come a long way.
More specifically, "only" 2 weeks to issue a security fix is actually pretty good for thick client/desktop software. It's less than ideal for something like a web app where they control all the machines that need to adopt the fix, but still. Also, the severity of reported issue is a factor in when something gets fixed.
Consider looking at something like rfp's RFPolicy if you'd like guidance on how to disclose in a reasonable, timely way
I was only voicing my personal experience, which has been very poor (maybe the team, or the seriousness of the bugs), but in general I have heard some good things, especially for truly critical issues.
When did Facebook become the pinnacle of security response? The last thing I read about them was pretty horrible. Much worse than the Microsoft response here.
That's actually even more of a reason to migrate away from Microsoft.
True, none of those were security issues.