re: "Windows DID it."
I'm not sure what you mean by that, DGpeddler, but it sounds like you ascribe the blame to Microsoft.
Stuxnet incorporated not one, but three, zero-day vulnerabilities. That is, it took advantage of three system flaws that no one in the world had previously known. Obviously, there were no patches or antivirus signatures to guard against them. They were unknown, even to the manufacturers/developers of the products. And although Stuxnet ran on Windows, the vulnerabilities it exploited were not all Microsoft's.
When a company markets software internationally, most countries require the company to provide the code prior to granting it permission to sell the product. The governments then go about analyzing the code, looking for anything that might be a concern, but also identifying vulnerabilities which they typically keep to themselves.
Such zero-day vulnerabilities are rare gems. Stuxnet had three.
Rogue hackers could never have implemented it. They don't have access to the product code. From that alone, it is clear that Stuxnet was the work of one or more nations, not individuals, confederations or companies.
Whoever designed Stuxnet had an OUTSTANDING understanding of the Bushehr nuclear power plant, its layout, its construction, its security, its people, and the automated systems within. They built the first product to ever attack programmable logic controllers, the Siemens mechanisms that regulate industrial hardware, ensuring that the hardware operates within specified boundaries.
It's said that the attackers had to have understood the Iranian facility better than the Iranians themselves - which is actually possible since the facility was built with extensive foreign assistance, and stocked with foreign technology.
Finally, whoever was behind Stuxnet compromised Verisign digital certficates for TWO high tech companies far removed from Iran. No hacker could have pulled that off. In fact, the compromises almost had to have involved breakins at Verisign itself, altering Verisign's records so that the certificates would give Bushehr the 'thumbs up' to communicate with the Command and Control servers from which Stuxnet received guidance and delivered findings.
Could one company (Microsoft) have been behind such an attack? Not a chance. Stuxnet went far beyond the resources available to Microsoft. It is not even likely that Israel or the United States could have been behind it. Not by themselves. Stuxnet was probably a coordinated effort by several determined governments.