>
unconscionable makes it sound like it's more irresponsible than the industry standard - when in fact it is less.
> Yes, I agree that's a stupid call to make, but most smartphones have far worse unpatched vulnerabilities.
That's why Apple's response here is so interesting: it's much more common for smartphones to have serious and known unpatched vulnerabilities than it is for desktop and server operating systems to have them.
It's expected that a smartphone might go unpatched for a while, but the industry standard is that a desktop or server operating system should receive a patch for an extremely severe security vulnerability almost immediately.
Why Apple has chosen to ignore and invert that expectation is unclear. Was there an active, seriously damaging attack against iOS that they thought needed to be stopped right away, despite the cost to OS X users? Did they look at the install base and decide patching iOS first would have a larger impact? Is their development process for OS X not up to the task? Do they just care a lot more about their consumer electronics than their computers?
Then there's the question of why they published the details of the iOS patch before publishing a patch for OS X. Perhaps they rushed to patch iOS when they discovered the vulnerability without realizing that OS X is affected as well? The situation raises a lot of questions--while I'm not sure that what has happened is unconscionable yet (rather than merely extremely incompetent but well-intentioned), it's still an open question, and it's certainly possible.