Perhaps there is some middle ground between not communicating with security researchers for *months* about open holes, and running a fully secured system?
I don't think it's asking too much to plug wide open holes that are already public. It's not like it's the first time.