I don't understand the logic of cause & effect the author laid out.
Commercial software with well-paid programmer employees also have long lists of CVE/RCE including MS Windows, Azure, AWS, Adobe PDF reader, Oracle database, etc.
I think the crux of the author's argument is the 2nd paragraph:
>Like many projects, Log4j is only maintained by volunteers, and because of this, coordination of security response is naturally more difficult: a coordinated embargo is easy to coordinate, if you have a dedicated maintainer to do it. In the absence of a dedicated maintainer, you have chaos: as soon as a commit lands in git to fix a bug, the race is on: security maintainers are scurrying to reverse engineer what the bug you fixed was, which is why vulnerability embargoes can be helpful.
Exactly how does a permanent paid $100k salary change the "vulnerability embargo" window in this particular case?
E.g. the log4j JNDI code fix was night of December 4: https://github.com/apache/logging-log4j2/commit/d82b47c6fae9...
The widespread news of the RCE was December 9.
How does extra funding change the timeline and coordinate a better embargo? Or asked another way, how do the commercial vendors manage voluntary information embargos better because they have dedicated paid staff?