> the disclosures put our customers at unnecessary risk.
That statement irks me. Responsible disclosure or not, It's Microsoft themselves that put their customers at risk, not the researcher.
Especially since the only explanation for why this exists is as a backdoor.
The industry, on average, approves of responsible disclosure because there's a tacit agreement that making risk-proof software isn't feasible. Though admittedly some companies don't seem to be trying very hard anymore.
It's not a dichotomy either, they can both have put the customers at risk.