> That doesn't excuse the mistakes on Apple's part.
Let's first establish that Apple definitely has a stake in this.
How long they can come up with a fix and then distribute them, that's a question. You can't expect any company to fix a vulnerability within 5min. Whether one week is too long or their delivery mechanism is good, I can't tell, and I don't think there is a standard in the entire industry.
That doesn't mean it's useful to write an article about "I didn't do my part BUT you are too slow". Even if Apple somehow fixes this within an hour of the disclosure and delivers the update, with the bad configuration, the machine is still vulnerable within that window. Does that change the nature of the narrative?
I don't think anyone criticized the timing of the patch.
But I find it egregious that they didn't roll it out as a security update at all, which is why it was not automatically installed in OP's case, even though the fix was already available.
I mean, what else requires a hotfix via security update if not a fatal flaw in your remote access authentication leading to full root access, that is actively being exploited in the wild?
Also, it's not really on the user to gate remote access behind an additional firewall and authentication layer. This is something that just has to work securely.
If it doesn't, that's understandable, but still hardly the user's fault.