RE: bill gates' claim about security vulnerabilities per LOC inUnix versus Windows

"L. Adrian Griffis" <[email protected]>
Newsgroups gmane.comp.security.programming
Message-ID <[email protected]>
On Wed, 5 Nov 2003, Cobus Neethling wrote:
> In stead of raising my own oppinion I am quoting a news item from
> viruslist.com run by Kaspersky Labs. You can find the article online at
> http://www.viruslist.com/eng/index.html?tnews=1008&id=56937
>
> [..]
>
> Attacks:
> MI2G reports attacks on Linux is on the rise -
> 5,736 attacks in the whole of 2001, but the first half of 2002 already shows
> 7,630. While attacks on Windows systems running Microsoft's IIS Web server
> fell by 20 percent, from 11,828 during the first six months of 2001 to 9,404
> over the same period this year. These figures do not include viruses and
> worms.

The figure described is on "attacks".  How many of these attacks were
successful.

> Bugs and Vulnerabilities:
> The firm, Internet Security Systems last year, 2001, identified 149 bugs in
> Microsoft software and a surprising 309 for Linux. This year, 2002,
> continues this trend with a whopping 485 bugs attributed to Linux and a more
> sober, but still "way-too-high" 202 for Microsoft. More recent Microsoft
> offerings, such as Windows XP are indeed harder to crack than previous
> Windows products and may also offer a partial reason why Linux is now more
> often a target.

Is this the often quoted spin from MS, where each Linux vulnerability is
multiplied by the number of major distributions, because each distribution
owner makes his own separate announcement of the problem and the patch?
Any given Unix/Linux system runs only runs one flavor of Unix or Linux,
and only needs to worry about announcements specific to that flavor.

Also, how many of those problems are actually fixed?  The Unix/Linux
community see's these problems as bugs and tries to fix them.  How many
times has MS left the bugs in place and told it's customers to get a
firewall or to get a virus scanner?  If I have to tolerate half of the
last five years worth of MS bugs (because they only admit some of them
are bugs) but I only have to tolerate the last year of Linux bugs, then
the bug announcement per year thing isn't really that good an indication
of the risks I face.


Don't get me wrong, Unix and Linux flavors should be judged by the same
standards of every other OS.  But like any other area of research, its
a study's worth is very much dependent on methodology.  You have to
make sure that the thing you are interested in is what's really being
measured.  There's nothing wrong with sound criticism of Unix and Linux,
but that article was pure spin.  Tell us what's actually being measured,
or we can't even begin to decide if it's meaningful.

It takes time to learn to tell the difference between good methodology
and bad, but it's worth the effort.  That article is particularly
meaningless because they don't even care enough about methodology to
tell us where their numbers come from.  No one should be swayed one
way or the other by that kind of drivel.

Adrian
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.