This is pretty standard, timeline-wise, for most responsible disclosure policies. As-in : Give the vendor ample time to publish and deploy a fix before reporting vulnerability specifics.
Aside: As usual, excellent work from Google project-zero
I get that, but I wasn't commenting on that. I was commenting on the Hacker News title being misleading.