RE: bill gates' claim about security vulnerabilities per LOC inUnix versus Windows

"Alexandre Sieira" <[email protected]>
Newsgroups gmane.comp.security.programming
Organization Cipher - Segurança da Informação
Message-ID <[email protected]>
	I forgot to write one final comment on the issue of the number of
bugs found in Linux against those found in Windows.

	I have to say that bugs being "found" is not a problem. It is their
existance that is a real problem.

	The fact that more bugs are found on Linux does not mean that Linux
_has_ more bugs, which is the hidden inference on that paragraph.

	We have to keep in mind that Windows is developed in a closed-source
model. In that model, Microsoft employs quite a large number of people to
test and debug any software during its development and prior to its release.
The bugs found in this process are never counted on any external statistic,
because the bugs that actually reach the users are the ones that survived
the testing and SQA process.

	Linux, however, has no such secrecy. All the bugs found during the
development process are necessarily known to public, because it is by
definition on a constant development process.

	So, to further clarify the e-mail from viruslist.com, the fact that
Linux has more publicly known bugs is a consequence of its development
process. A fair comparison in that regard could only be reached if
Microsoft´s internal SQA statistics on the number of bugs fixed was added to
the publicly known bugs after release, and that number compared to the
number of Linux bugs.

	I do not mean to say by the previous arguments that Linux is a safer
OS than Windows, even though I personally do believe it to be. I am just
saying that the arguments presented in the e-mail from viruslist.com are
ill-formed, cannot be used to reach the implied conclusions, and seem very
biased.

--
Alexandre Sieira, CISSP
Cipher - Segurança da Informação
+55-21-2529-2629
www.ciphertech.com.br
 


> -----Original Message-----
> From: Cobus Neethling [mailto:[email protected]] 
> Sent: quarta-feira, 5 de novembro de 2003 04:41
> To: [email protected]
> Subject: RE: bill gates' claim about security vulnerabilities 
> per LOC inUnix versus Windows
> 
> 
> In stead of raising my own oppinion I am quoting a news item 
> from viruslist.com run by Kaspersky Labs. You can find the 
> article online at 
> http://www.viruslist.com/eng/index.html?tnews=1008&id=56937
> 
> Here goes...
> 
> 
> VirusList.com Virus Alerts & Virus News. Thursday, October 03, 2002
> ******************************************************************
> 
> 1. Linux Gets A Reality Check
> 2. How to subscribe/unsubscribe
> 
> ****
> 
> 1. Linux Gets A Reality Check
> It may not be a surprise that as Linux diligently plods 
> forward with a 30% annual increase in usage it is being 
> targeted more and more by hackers, however, what may be a 
> surprise is that Linux is proving to be at least as 
> vulnerable as Windows products. While Linux has long basked 
> in its reputation as a secure and stable platform, 
> Microsoft's Windows is famously maligned for its bugs (what 
> Microsoft terms "issues") and security vulnerabilities. It 
> now appears that more than a few, especially virtually every 
> proponent of the Linux open source revolution, may owe an 
> apology to the Redmond, Washington software "monster", though 
> presumably Bill Gates and his team are not holding their 
> collective breath. Seemingly Microsoft's biggest crime was 
> its popularity. 
> 
> Attacks: 
> MI2G reports attacks on Linux is on the rise -
> 5,736 attacks in the whole of 2001, but the first half of 
> 2002 already shows 7,630. While attacks on Windows systems 
> running Microsoft's IIS Web server fell by 20 percent, from 
> 11,828 during the first six months of 2001 to 9,404 over the 
> same period this year. These figures do not include viruses and worms.
> 
> Bugs and Vulnerabilities: 
> The firm, Internet Security Systems last year, 2001, 
> identified 149 bugs in Microsoft software and a surprising 
> 309 for Linux. This year, 2002, continues this trend with a 
> whopping 485 bugs attributed to Linux and a more sober, but 
> still "way-too-high" 202 for Microsoft. More recent Microsoft 
> offerings, such as Windows XP are indeed harder to crack than 
> previous Windows products and may also offer a partial reason 
> why Linux is now more often a target.
> 
> Notes: 
> XP may indeed be more secure than older Windows products, 
> however, it should be noted that many networks run older 
> Windows versions as well, thus mitigating the security 
> improvement brought by XP.
> 
> Another notable trend is the emergence of hybrid viruses that 
> attack multiple platforms. One such example is Nimda, which, 
> besides its preferred victim Windows, also managed to infect 
> AS/400 and Solaris machines.
> 
> Statistics and trends aside, the most important thing is that 
> users follow a sound security policy and regularly update 
> anti-virus and other security software.
> 
> 
> 
> **
> 
> 2. How to subscribe/unsubscribe
> 
> If you would like to subscribe to other news blocks or to 
> unsubscribe from this news block, you can do so by visiting 
> http://www.viruslist.com/eng/maillist.html
> 
> If you experience 
> any problems with this procedure, please contact us at: 
> [email protected]
> 
> ****
> 
> Best of Luck,
> 
> Kaspersky Lab News Agent
> 
> -----
> 10 Geroyev Panfilovtcev St., Moscow, 123363, Russia
> Telephone./Facsimile: +7 (095) 948 43 31
> WWW: http://www.kaspersky.com, http://www.viruslist.com
> FTP: ftp://ftp.kasperskylab.ru
> E-mail: [email protected]
> 
> 
> Cobus Neethling
> Web Developer
> CKNet Internet Services (PTY) LTD
> Tel: +27 11 314 0171
> 
> 
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.