Re: bill gates' claim about security vulnerabilities per LOC in Unix versus Windows
| Newsgroups | gmane.comp.security.programming |
|---|---|
| Message-ID | <[email protected]> |
On Tue, 04 Nov 2003 20:43:47 -0300, gr00vy said: > I think there is a main thing nobody has noticed about vuln per line of > code. We do not have windows code, if some day we will have the > oportunity to read it i'm very shure that it will be full of security > bugs. > i think thats the main difference between this kind of OS, the sames > acts on closed src appl. On the other hand, although the claim is that "with enough eyeballs, all bugs are shallow", there's no guarantee that just because it's open source that all the bugs will be found. For instance, Sendmail has been open source its entire lifetime - and some of the recent bugs have been in *VERY* old code (I'd have to ask Eric, but I think I remember seeing crackaddr() back in version 5.mumble on a Vax 750 going on 2 decades ago now...)
signature.asc
(application/pgp-signature, 226 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.2 (GNU/Linux) Comment: Exmh version 2.5 07/13/2001 iD8DBQE/qGvmcC3lWbTT17ARAuThAJ9PSDGiuiJ14g8wm4PzFlXfO6DpaACeJPSV xrS4Lja/5PleXxW4HHLBiu4= =tUr3 -----END PGP SIGNATURE-----