real_aurgathor Evidence suggests that those at ZuckerCorp don’t exactly have a solid grasp on the concept of irony. Of all the companies on Earth, they are the ones spouting overtures about important steps forward for privacy and security? This, the same company that had "Pixel"s implanted in tax software and health-related Web systems in order to surreptitiously collect the most private data on users of those products, without permission, and even for people who had never agreed to any of their terms? The same company that amasses “shadow profiles” on people who don’t use its services? That is the company that is talking about privacy? So, Mark, are you the pot, the kettle or the whole stove?
Also, what does it mean when one claims that someone “unlawfully exploited a bug”? Since when is it illegal to exploit unpatched vulnerabilities? And if it is, then why isn’t it illegal not to patch such vulnerabilities in a pre-determined amount of time? To me, this suggests that there needs to be a wider discussion on the details of vulnerability reporting and vendors’ responses to said reports, with internationally-agreed-upon standards, and even legislation if needed (and recent corporate behaviour suggests that legislation is warranted). Lately, it seems that vendors are so focused on sales, profits and cost-cutting that essentials like testing, security and usability are taking a back seat (or worse).