Microsoft and outside security researchers accused a Google engineer of failing to follow the responsible disclosure etiquette his own company promotes by disclosing a Windows XP-related flaw on Thursday, publishing code to exploit it and giving Microsoft only five days to fix it.Tavis Ormandy informed Microsoft about the vulnerability–located in the online Windows Help and Support Center feature that offers customers technical support–on Saturday. He then announced details of the hole and offered proof-of-concept attack code in a post to the Full Disclosure security e-mail list on Thursda
http://news.cnet.com/8301-27080_3-20007421-245.html
Gordon “Fyodor” Lyon, a network security expert and a former president of Computer Professionals for Social Responsibility, praised Ormandy’s research but did not address whether his releasing the exploit was a good thing or not.