Re: bill gates' claim about security vulnerabilities per LOC inUnix versus Windows
Barry Fitzgerald <[email protected]>
| Newsgroups | gmane.comp.security.programming |
|---|---|
| Message-ID | <[email protected]> |
Cobus Neethling wrote:
>
>Bugs and Vulnerabilities:
>The firm, Internet Security Systems last year, 2001, identified 149 bugs in
>Microsoft software and a surprising 309 for Linux. This year, 2002,
>continues this trend with a whopping 485 bugs attributed to Linux and a more
>sober, but still "way-too-high" 202 for Microsoft. More recent Microsoft
>offerings, such as Windows XP are indeed harder to crack than previous
>Windows products and may also offer a partial reason why Linux is now more
>often a target.
>
>
>
I've never supported blanket bug counts when comparing MS Windows to
GNU/Linux.
Which GNU/Linux distribution were they referring to?
Does the bug count include the umteen hundred packages that have no
counterpart in the Microsoft world? (like local buffer overflows in
games that let people change other's scores and stuff of that ilk?)
These numbers are useless, their statistical context is completely left
blank.
Be VERY VERY careful about using statistics. I know that you didn't
write that, Cobus, but statistics like these are thrown around WAY too
much to be useful. And that goes for either side of the argument.
-Barry