RE: bill gates' claim about security vulnerabilities per LOC in Unix versus Windows
gr00vy <[email protected]>
| Newsgroups | gmane.comp.security.programming |
|---|---|
| Organization | Linux User -- ZenCracking.com.ar |
| Message-ID | <[email protected]> |
I think there is a main thing nobody has noticed about vuln per line of code. We do not have windows code, if some day we will have the oportunity to read it i'm very shure that it will be full of security bugs. i think thats the main difference between this kind of OS, the sames acts on closed src appl. It is my honest thougth Cheers gr00vy from argentina (Sorry about my english) On Mon, 2003-11-03 at 17:23, Thompson, Michael wrote: > Hi, > A very interesting series of studies at > http://www.cs.wisc.edu/~bart/fuzz/ may provide some interesting > (perhaps, somewhat dated) empirical data for this discussion. Although > it has been some time since I've read these papers and I don't believe > their results are expressed in terms of bugs per line of code, I think > the information is pertinent to this discussion. > > Mike > > -----Original Message----- > From: [email protected] [mailto:[email protected]] > Sent: Friday, October 31, 2003 6:07 PM > To: [email protected] > Subject: bill gates' claim about security vulnerabilities per LOC in > Unix versus Windows > > > in an interview done after his speech at the ms developer's conference, > http://www.itbusiness.ca/index.asp?theaction=61&sid=53897 > bill gates claims (among other things)... > > ..."The fact is, there are security vulnerabilities in peoples' > applications in many places. I mean, people act like some other systems > don't have vulnerabilities; actually all the forms of Unix as well as > Linux have had more vulnerabilities per line of code. They don't > propagate as much because they're not as dense as our system is, so the > things that prevent the propagation are particularly important for our > world."... > > The "density" claim I think refers to the distribution of Windows > systems, densely packed on the agar dishes of corporate lans. > > But does anyone actually know what studies might have compared > vulnerabilities per LOC among different operating systems? > > the distinction between "bugs" and "exploitable vulnerabilities" > may come to bear. > > or maybe the huge number of lines of code in the denominator is what > makes this claim is based on. -- -----BEGIN PGP PUBLIC KEY BLOCK----- Version: GnuPG v1.2.1 (GNU/Linux) mQGiBD+MWD0RBAD0zsMD23euntPmXJScQ6aqId4s6SGHw5FdcgSdxM2rRo1/HJ10 yZhApRGKCbnM/RW8P1+pIKlKBvSIp9wmeIgikz4KGmzGIfuhaHwzVOTEBmY3PBqn Q73LLC+tsUPRDDuEQY5OmtbiukRmCBWFezAzFOmD3RhbgjtkGXP3nCfKbwCgnMDh /cBR9cMJDJSBnt+s3odafjMD/io6JbwCL7s3EUjU/QtNI3Zwflm/biPjMu0++wIb IEtfTLKiAKWGpnoIVjPe8bH6uQgbp4n8G1fFkkvlmvXc2Yz012MFLJyyJLRLg4L1 ZG72ExhGz54D3GV9t5VqG9IsNfDSYrH/GC6zE6N2jRFL/e6K/sg82zZqBGRpkmdM 48xyBACuNgIWtPpaMdM+WeC7nh6+j5E5eT+x1RinDHGH95y4gpKBhBr/Yc4nQvh5 e07wHHO4iWuTrnCbxEaKFOk1iTY3b1eZXZvcdJPiyq2nfp7OoRs69JZ40HQSA+aF O60rlEh8UgnD3fDD9/JzxW3iAdDPk8BLuoAC1Qdt1qpbhv0UkrQ1Z3IwMHZ5ICha ZW5DcmFja2luZy5jb20uYXIpIDxncm9vdnkyNjAwQHlhaG9vLmNvbS5hcj6IWQQT EQIAGQUCP4xYPQQLBwMCAxUCAwMWAgECHgECF4AACgkQTKxJeVJCmvAmrwCfZSL3 bx1vyW4pTNwyez0fdOJmQ+EAoIOUDo0aO9LdfpruyrTzvkQaOlnSuQENBD+MWD4Q BADcytQOgY+pPtQdgKTn53VIEOzyagqNdfd3ei0K+TIEl9x9rdOwYWn5bf8m6QIn EgWi9+cvvXIl7+ziHUOCyx/BmB3bNQ9TSIlrpx+S42BJvTAJEb0hTDn6FkeupBea edxCyt25hJjb0NoMhn32kDiWIEGqh16Tt+h0W6MbFVDilwADBQQAmY+DT5cx6u9Y urffLDVq2/FHUncJQ5jIZy+ThqRWG+DBg46UzGqSIZzXhyB49k1EBgTPA8d8rJML fLnre1ccRvzo++VR6iIEAX5ur2mosM2SCePbJ4yTugkFPGt7dfgnQnWhNMO8GMYo x0HyN+VM72VmqEKG+k7c5cVZ8GvEH4uIRgQYEQIABgUCP4xYPgAKCRBMrEl5UkKa 8ILrAJoCQOtCNlNOdbImuMTLu8hN9GHgiACgkQZQTHy1ielq23Vyl0A5Vy98bkQ= =LiOi -----END PGP PUBLIC KEY BLOCK-----