Windows is very popular.
Windows is very popular.
https://googleprojectzero.blogspot.com/p/vulnerability-discl... https://googleprojectzero.blogspot.com/2020/01/policy-and-di...
Leaving vulnerabilities in products for an extended period of time is a problem, and adding a deadline helps to ensure that important security issues actually do get triaged and addressed.
As a recent project zero blog post about their policy calls out (https://googleprojectzero.blogspot.com/2020/01/policy-and-di...) "We've seen some big improvements to how quickly vendors patch serious vulnerabilities, and now 97.7% of our vulnerability reports are fixed within our 90 day disclosure policy."
It sounds like it's working as intended. The only way you can make it actually work is to make sure it has some teeth though, hence you have to actually disclose when you say you will.
> doesn't it cause more harm than good?
Microsoft is harming its users by not fixing a security vulnerability. In this case, it's even more clear since there's "in the wild" exploits. Project zero's just helping to raise awareness of the harm microsoft's causing.
The stakes are very different for disclosing a remotely exploitable vuln.