As a hoster I truly despise this individual. Back in the dying days of Windows 2003 he did the same thing. We still had a small fleet of 2k3 servers on extended maintenance in our shared hosting environment.
This prick saw fit to release details on a "zero day" after 90 days which caused us some serious pain and major loss of business. Sure MS should have moved faster to plug the hole, but you know, Windows is a helluva legacy code base, but this arrogant ass-hat still saw fit to effectively fuck us and a few other UK hosters by releasing the exploit details.
Literally within 48 hours these boxes were pwned (via insecure/broken versions of Wordpress and other shit code agencies write - sadly as a shared hoster you simply can't control what 2000 users do on their shared hosted sites with PHP and ASP). It was a privilege escalation exploit, goddamn nothing we could do to prevent this.
Ok, I get the "security through obscurity" argument, and that we shouldn't hide these exploits, but at that time there were no known exploits in the field....until Tavis told the world.
He's got a chip on his shoulder about Microsoft and their past security practices (fair enough, I have too), but he seems to not give a shit about the impact of releasing a zero day, that perhaps only he knows about, on businesses trying to earn a crust. Not very responsible.
Sorry for the bad language, but when you've been up for five days solid fire fighting this type of crap my respect for the likes of Ormandy (and MS for not moving fast enough) kinda goes out of the window.
I expect many to disagree and perhaps revel in disrupting MS's platform, but there's a social and moral responsibility. What good does it do to release these exploits after some arbitrary amount of time Ormandy and crew have decided when it's likely only them at that time who understand them. Businesses live and die sometimes by these decisions, and the impact on their staff can be catastrophic.