Re: bill gates' claim about security vulnerabilities per LOC in Unix versus Windows
Barry Fitzgerald <[email protected]>
| Newsgroups | gmane.comp.security.programming |
|---|---|
| Message-ID | <[email protected]> |
David E. Mollico Jr wrote:
>*laughs*
>You all are funny if you think one of the richest men in the world would
>make a claim nationally that he couldn't back up with studies and facts.
>I'm sure some of you might reply saying he fakes the studies or does
>something to hurt them or make them bias. Fact is, microsoft has some of
>the best products out there.
>They hold some of the most sensitive information in the world. Hense,
>they are attacked more than anything else in the world.
>
>
>
And what, pray tell, would his being rich have to do with the validity
of his claims?
If you believe that the amount of money that someone has bears any kind
of direct correlation with the honesty or accuracy of their statements,
then you might as well say that 90% of the populace are bald-faced liars
and that the wealthy are completely honest and accurate all of the time.
It should be fairly obvious that history does not show these statements
to be even remotely true.
If I were to read your comment on a news site, I'd be forced to claim
that it was a troll, simply because of the relative baselessness of it's
claims. But, then, I suppose one does not need to be able to back up
their opinions to have pure blind faith in them (which is precisely what
you're expressing in the above message). History is repleat with people
who made very bad decisions based exclusively on blind faith.
Your logic, and Gates' logic, are flawed in multiple respects:
1) I've never seen a truly good study on propagation escalation based on
host-density, which is really what Gates is referring to. The few
studies I have seen actually base their results on what can only be
determined to be microcosms when compared to the Internet. And yes, in
those situations all worm and exploit propagation is exponential in
nature, but in this case I would argue that the scale cannot be
generalized. Once you reach a certain point in propagation, resource
consumption dictates that your propagation will level off considerably
and that exploit will level off with it. Hence the argument "well, we
have more hosts on the net and thus, will be exploited more frequently",
albeit simplistically true, is also highly flawed once you are comparing
two samples of great size (like the installed Windows base -vs- the
installed GNU/Linux base, which are both sizable in number).
2) Number of security issues per LOC is a nice statistic, but that's all
it is. It does not reveal precisely what the issues were, nor does it
shed any light on how exploitable they were. Those who believe that all
issues are equal, are horribly mistaken. So, this claim is largely
dubious and barely worth discussing from a statistical standpoint. It's
essentially worthless and meant to deceive people. Note: I'm not saying
whether Gates' statement is accurate or not. I'd venture that that's
probably conditional to the operating system that is being referred to
in the comparrison. Blanket statements of this sort are very difficult
to prove and, I'd wager, that alone sheds doubt on the statement.
3) The value of data being stored is not relevant to the discussion. I
would argue that important data is often stored on Unix-based systems,
so therefore the same statement can be made with *nix replacing MS
Windows. Crackers are willing to penetrate whatever they can. Some
shoot for the value of the data on the system, but that is not the
exclusive goal in system exploit, and the information on the system
being cracked is probably not the prime motivator of the majority of
exploits. More often, most exploits are carried out in order to gain a
foothold on a network. One of the reasons that people do so is to get
at the information on a target machine on the network, but that is not
the only reason that such a foothold can be attained. You're limiting
yourself by applying your experience of the world and your motivations
to others. That is somewhat presumptuous and will ultimately fail you.
Simply friendly advice. :)
-Barry