I'm sorry, but you don't seem to understand how an *effective* task force operates. Companies, especially large ones, don't need or *want* some external agency telling them how to run things. If Microsoft or Google or Amazon (or anyone else) wanted to fix their well-known problems, they'd just do the right thing and *fix them*. The only reason to get involved here is to gum up the works, and that's already obviously the case based on the recommendations listed. You really don't have a leg to stand on until you show evidence of the task force seeking to bring down the hammer (or even a fly swatter) on the companies that create insecure software in the first place. 4b31fa42dc4daad34425e10bf3ada6108d3024af7273e83b8275a8bb58a75ceb