Microsoft is one of the least careless companies about security in the entire industry, and particularly so when it comes to cryptography. It's just a very big company, and they don't (or didn't, last I checked) have a cryptography review board the way Google does, to make sure people like Niels Ferguson get their eyes on all their crypto-bearing features.
> don't (or didn't, last I checked) have a cryptography review board the way Google does,
Exactly my point. Every company follows standard security policies. But for a company like Microsoft, given the responsibility it has and the profits it makes and the amount of money it’s executives make is it unreasonable to expect more?