Microsoft gives Windows app developers 180 days to patch -- or else
Microsoft today said it would give third-party app developers 180 days to clean up their security act -- and patch serious vulnerabilities -- or the company will yank their software from its online stores.
One impressed security expert called the move unprecedented. "I'm really happy with the public details on how they'll handle this," said Tyler Reguly, the manager of security research at Tripwire. "I'm not aware of similar public policies for Google Play or the Apple App Store."
The new policy was announced by the Microsoft Security Response Center (MSRC) Tuesday alongside the release of July's Patch Tuesday flaw-fixing slate. Effective immediately, developers must fix vulnerabilities in their apps rated "critical" or "important" -- the top two rankings in Microsoft's four-step threat-scoring system -- within 180 days of being notified by the MSRC. The penalty for failure: Microsoft will remove the vulnerable app from the pertinent app store.