I feel the 2 US companies have a friendly competition with each other which can help secure their systems.
I feel the 2 US companies have a friendly competition with each other which can help secure their systems.
There are certainly companies doing much worse than setting 90 day deadlines. For example VUPEN, Hacking Team, and GrayKey selling undisclosed vulnerabilities to "good" governments, and other companies servicing the shadier governments[1].
[1] https://www.bloomberg.com/news/features/2017-01-18/the-post-...
Surely it means specific people employed by Google may "speak". Does the right extend to corporations?
Imagine that world. I point out a mistake to you, and by reading or hearing it, you are suddenly holding a gun! We would have to criminalize coredumps :)
Unfortunately it does, to some degree.
Religious freedom too. The US is fucked.
If they mess up a patch it's a big deal. If they break systems, introduce further bugs, etc...
90 days to understand the problem, fix the bug, verify the fix, plan the release, get it out to customers. There is a lot of work involved in such a thing.
Once you go life or death situations, regulatory environment applies, backward compatability matters, ... Everything takes endless. It is not code, commit, test and deploy. Intake, Risk Analysis, project planning, approvals, alignments, etc. So many more processes. We should not fool ourselves that other platforms are better in that once you go for serious SLAs. Linux Kernel or user land patch might be fast, but RedHat delivery will take longer.
Welcome to Enterprise development.
When enterprise just falls on its face, I don't have much sympathy. "So many more processes" sounds like taking a handful of steps, splitting them up, and making each one require multiple days of memos back and forth. Can you provide any justification for this? Am I misreading?
That is assuming whoever you are replying to is foreign to enterprises.
Microsoft has set up a patch delivery infrastructure that's pretty effective and comparably fast by industry standards, if not deactivated by the people who got offended by the forced Windows 10 upgrade and feature creep.
Add to it Microsofts well established unwillingness to provide any useful diagnostic information and suddenly the only way to use the machine is to not update it.
For a bug with completely unknown scope and very difficult fixes (such as the recent intel issues) the story might be different. But 90 days here? Why would Microsoft need more than that?
It sounds like some other piece of MS software is relying on .NET not performing the checks that it should have been performing.
They own an operating system. We get to hold them responsible for whatever choices they make that impact security.