Comment Re:Immediate full disclosure is best security prac (Score 1) 801
They should at least have the chance to do it. For me, 72 hours seems like a reasonable timeframe for Microsoft to reply to his report. If they didn't, _THEN_ go public.