How Microsoft ranks with the most tardy bug fixers
When HP’s TippingPoint issued an ultimatum Wednesday to software vendors to fix and reveal to the public software vulnerabilities within six months, Aaron Portnoy, manager of security research at TippingPoint, directed me to a page on the company’s Zero Day Initiative (ZDI) site that lists all the vulnerabilities known to ZDI and to the software vendors but for which a patch hasn’t yet been developed; details of the vulnerabilities are kept under wraps until a patch is available so as not to give hackers a road map to exploiting them.
Although Microsoft software is ubiquitous globally, regularly has to admit glitches in its software and is notorious for buggy software, Microsoft actually came out looking good, at least in the snapshot I found on the site today.