Re: bill gates' claim about security vulnerabilities per LOC in Unix versus Windows

Barry Fitzgerald <[email protected]>
Newsgroups gmane.comp.security.programming
Message-ID <[email protected]>
David E. Mollico Jr wrote:

>*laughs*
>You all are funny if you think one of the richest men in the world would
>make a claim nationally that he couldn't back up with studies and facts.
>I'm sure some of you might reply saying he fakes the studies or does
>something to hurt them or make them bias. Fact is, microsoft has some of
>the best products out there.
>They hold some of the most sensitive information in the world. Hense,
>they are attacked more than anything else in the world.
>
>  
>

And what, pray tell, would his being rich have to do with the validity 
of his claims?

If you believe that the amount of money that someone has bears any kind 
of direct correlation with the honesty or accuracy of their statements, 
then you might as well say that 90% of the populace are bald-faced liars 
and that the wealthy are completely honest and accurate all of the time.

It should be fairly obvious that history does not show these statements 
to be even remotely true.

If I were to read your comment on a news site, I'd be forced to claim 
that it was a troll, simply because of the relative baselessness of it's 
claims.  But, then, I suppose one does not need to be able to back up 
their opinions to have pure blind faith in them (which is precisely what 
you're expressing in the above message).  History is repleat with people 
who made very bad decisions based exclusively on blind faith.

Your logic, and Gates' logic, are flawed in multiple respects:

1) I've never seen a truly good study on propagation escalation based on 
host-density, which is really what Gates is referring to.  The few 
studies I have seen actually base their results on what can only be 
determined to be microcosms when compared to the Internet.  And yes, in 
those situations all worm and exploit propagation is exponential in 
nature, but in this case I would argue that the scale cannot be 
generalized.  Once you reach a certain point in propagation, resource 
consumption dictates that your propagation will level off considerably 
and that exploit will level off with it.  Hence the argument "well, we 
have more hosts on the net and thus, will be exploited more frequently", 
albeit simplistically true, is also highly flawed once you are comparing 
two samples of great size (like the installed Windows base -vs- the 
installed GNU/Linux base, which are both sizable in number). 

2) Number of security issues per LOC is a nice statistic, but that's all 
it is.  It does not reveal precisely what the issues were, nor does it 
shed any light on how exploitable they were.  Those who believe that all 
issues are equal, are horribly mistaken.  So, this claim is largely 
dubious and barely worth discussing from a statistical standpoint.  It's 
essentially worthless and meant to deceive people.  Note: I'm not saying 
whether Gates' statement is accurate or not.  I'd venture that that's 
probably conditional to the operating system that is being referred to 
in the comparrison.  Blanket statements of this sort are very difficult 
to prove and, I'd wager, that alone sheds doubt on the statement.

3) The value of data being stored is not relevant to the discussion.  I 
would argue that important data is often stored on Unix-based systems, 
so therefore the same statement can be made with *nix replacing MS 
Windows.  Crackers are willing to penetrate whatever they can.  Some 
shoot for the value of the data on the system, but that is not the 
exclusive goal in system exploit, and the information on the system 
being cracked is probably not the prime motivator of the majority of 
exploits.  More often, most exploits are carried out in order to gain a 
foothold on a network.  One of the reasons that people do so is to get 
at the information on a target machine on the network, but that is not 
the only reason that such a foothold can be attained.  You're limiting 
yourself by applying your experience of the world and your motivations 
to others.  That is somewhat presumptuous and will ultimately fail you.  
Simply friendly advice.  :)

                -Barry
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.