...acclaimed secure development process might not be working as advertised. They have a point. One would certainly expect its codereview process to have spotted and eliminated this particular vulnerability. It's remarkably similar to an earlier flaw...
http://www.computerweekly.com/blogs/david_lacey/managing-the-human-dimension/
...This article discusses: The codereview process Prioritizing your code... Finding Coding Errors The CodeReview Process Prioritizing Review...is not the only way to approach codereview, but it does form the basis for...
http://msdn.microsoft.com/magazine/cc163312.aspx