I think the issue is not the bug count, but that Microsoft tells Google "we will release a fix on day X," and Google says "X is past an arbitrary day we chose, so sad" and discloses a zero-day. Some people think it's an irresponsible PR stunt by Google, others that Microsoft would just put off fixes forever if Google didn't do this.
Maybe there's a similar story with OS X, but there doesn't seem to be a public record of it.
I meant to say that there would be zero days between when I could patch my (hypothetical) Windows machine, and when people could start hacking it. The Wikipedia article you linked elsewhere seems ambiguous, e.g. "It is called a "zero-day" because the programmer has had zero days to fix the flaw (in other words, a patch is not available)." Microsoft has had something up to 90 days to produce such a patch, but hasn't for whatever reason.
I really dislike your description because while it is technically true it heavily implies that they decided on dates on a per-bug case, when they decided on a flat 90 days.
Then again, 90 days contains 2.5 of their fix cycles. If the vulnerability really is serious, and they can't fix it in that time line, they should exit the business.
Google roughly supports one version of their product on 2 OSs.
Microsoft supports all versions of all their products for 10years+ after release, integrated with a combination of all other products they have shipped in that same time-frame.
Needless to say, Microsoft needs to do more QA on their bug-fixes before they can safely release it to all customers without the risk of causing new issues.
It's easy for Google to be big in the mouth when they don't bother to support their existing customers properly.
Speaking of being big in the mouth: Did you know that Google isn't back-porting security fixes to older versions of Android either (only 2 last minor releases)? I guess supporting more than 40% of your user base is too much work.</sarcasm>
Guess which side my sympathy is leaning to in this case.
> Needless to say, Microsoft needs to do more QA on their bug-fixes before they can safely release it to all customers without the risk of causing new issues.
IIRC Microsoft also releases pre-versions of their patches to select customers so sysadmins can test the patch doesn't cause issues on their deployments.
No, I think the "issue" is that Apple doesn't talk to the media, while Microsoft immediately complained to some big tech sites about it, which then wrote the story from Microsoft's point of view.
Even if we're talking about such a massive roll-out to millions of machines, with various versions of the OS running on various hardware? I don't know how easy or not the actual patch is to produce, but it's not out of the realm of possibilities that they did run into a compatibility issue that they wanted more time to sort out. Think of the outcry and damage to their business if they rolled out a patch that accidentally broke some installations.
Yes, even then. Imagine if the bug had been found by security researchers who believe in full disclosure. You think it's reasonable for Microsoft to allow dozens of rootkits and viruses to proliferate for more than three months, for botnets to grow to hundreds of millions in size? Microsoft's release process is broken.
Sure, three months is a long time to fix an issue, but what does Microsoft have to gain by taking longer to fix an issue of this severity than it believes it needs to? If Microsoft released the fixes when they were going to, and Google then released the details of the issues and when they first reported them, Google could still make a stink about Microsoft's turn-around time on critical security bugs, and there wouldn't be any gap between global notification of the issues and a readily available fix for them.
Put another way, Google may have just notified the world of black-hat hackers of an issue they weren't otherwise aware of, an issue that demonstrably will not be patched for some time. If that is the case, then Google just recklessly endangered people's computers in the interest of raising awareness of Microsoft's poor turn around time on these issues. There is also the very real chance that this issue was already known by the black-hat community, in which case there isn't nearly as much lost by reporting here, but that's a gamble Google is making in order to make a point.
And if we're talking about a true 0-day being exploited in the wild? Microsoft is still unable to get a patch out in less than 90 days time? That's flat unacceptable. They need to be more responsive than that.
Think what you want, but IMO 90 days (even rounded to the nearest patch Tuesday) is plenty of time to fix the critical security issue. Clearly Microsoft is acting weird here.
Maybe there's a similar story with OS X, but there doesn't seem to be a public record of it.