RE: bill gates' claim about security vulnerabilities per LOC inUnix versus Windows
"L. Adrian Griffis" <[email protected]>
| Newsgroups | gmane.comp.security.programming |
|---|---|
| Message-ID | <[email protected]> |
On Wed, 5 Nov 2003, Cobus Neethling wrote: > In stead of raising my own oppinion I am quoting a news item from > viruslist.com run by Kaspersky Labs. You can find the article online at > http://www.viruslist.com/eng/index.html?tnews=1008&id=56937 > > [..] > > Attacks: > MI2G reports attacks on Linux is on the rise - > 5,736 attacks in the whole of 2001, but the first half of 2002 already shows > 7,630. While attacks on Windows systems running Microsoft's IIS Web server > fell by 20 percent, from 11,828 during the first six months of 2001 to 9,404 > over the same period this year. These figures do not include viruses and > worms. The figure described is on "attacks". How many of these attacks were successful. > Bugs and Vulnerabilities: > The firm, Internet Security Systems last year, 2001, identified 149 bugs in > Microsoft software and a surprising 309 for Linux. This year, 2002, > continues this trend with a whopping 485 bugs attributed to Linux and a more > sober, but still "way-too-high" 202 for Microsoft. More recent Microsoft > offerings, such as Windows XP are indeed harder to crack than previous > Windows products and may also offer a partial reason why Linux is now more > often a target. Is this the often quoted spin from MS, where each Linux vulnerability is multiplied by the number of major distributions, because each distribution owner makes his own separate announcement of the problem and the patch? Any given Unix/Linux system runs only runs one flavor of Unix or Linux, and only needs to worry about announcements specific to that flavor. Also, how many of those problems are actually fixed? The Unix/Linux community see's these problems as bugs and tries to fix them. How many times has MS left the bugs in place and told it's customers to get a firewall or to get a virus scanner? If I have to tolerate half of the last five years worth of MS bugs (because they only admit some of them are bugs) but I only have to tolerate the last year of Linux bugs, then the bug announcement per year thing isn't really that good an indication of the risks I face. Don't get me wrong, Unix and Linux flavors should be judged by the same standards of every other OS. But like any other area of research, its a study's worth is very much dependent on methodology. You have to make sure that the thing you are interested in is what's really being measured. There's nothing wrong with sound criticism of Unix and Linux, but that article was pure spin. Tell us what's actually being measured, or we can't even begin to decide if it's meaningful. It takes time to learn to tell the difference between good methodology and bad, but it's worth the effort. That article is particularly meaningless because they don't even care enough about methodology to tell us where their numbers come from. No one should be swayed one way or the other by that kind of drivel. Adrian