The full timeline doesn't make big tech companies look particularly great. Heartbleed was a bug that came in with a questionable implementation of a questionable feature. It sailed through standards bodies and OpenSSL itself. A sensible explanation is that these are underfunded, understaffed efforts.
But next, the feature went live on the servers of more or less everyone, including Google and Yahoo and Amazon. People who employ and, presumably, well-compensate many experts in security and SSL implementations. Still, the code marched on, unnoticed, undisabled, deployed. How did that happen?
Big tech companies, small ones, and OSS folks, all write bugs. How does it "not look particularly great" to do something that literally every person writing software does. Wait, not even to do it. To miss the error in an obscure change in a backwater part of OpenSSL that no one uses. It does not strike me as likely that these companies review every change to every possible piece of sensitive software. The volume of work would be far too large.
I think the broader point being made is that practically anyone could come along and write code that then gets widely deployed. They just have to pick the right project, build up a bit of trust, and then submit a subtle but intentional bug. It's scary how easy it might be. It's not very clear how to defend against this.
But next, the feature went live on the servers of more or less everyone, including Google and Yahoo and Amazon. People who employ and, presumably, well-compensate many experts in security and SSL implementations. Still, the code marched on, unnoticed, undisabled, deployed. How did that happen?