11 points
It wasnt a serious security flaw, arguable not one at all. So they are perfectly justified in downplaying the hysteria.
4 points
the point is they could have fixed it by the time it was reported and not waited around until the issue was blown bigger.
3 points
A security company should prioritize investments (I.e. development time) depending on a threat model and risk management, not based on what random people think.
1 point
*