The irony of MSFT publishing this book (fun book btw) is they would go on to actively hunt down people discussing security issues, or reporting security issue to MSFT, attempting to have their employers fire them.
Other intimidation tactics were used as well.
Microsoft has admittedly come a long way in changing behavior and building a much better large scale SecDev process.
Still, I occasionally look at this book, the fact that it was published by Microsoft Press, and chuckle in confusion over the sheer cognitive dissonance.