Re: bill gates' claim about security vulnerabilities per LOC in Unix versus Windows
Jose Nazario <[email protected]>
| Newsgroups | gmane.comp.security.programming |
|---|---|
| Message-ID | <[email protected]> |
On Sun, 2 Nov 2003, Lucas Holt wrote: > If Microsoft has such secure software, then why do these "worms" > exploit only Microsoft products. Sure one can argue that Microsoft is > number one and therefore it would make sense to exploit windows on that > basis to hit a larger target. By now I would think someone would attack > linux or Mac OS X just to prove it can be done. The only linux worms i > am aware of only attacked apache. (there could be more) Of course on a > non windows system, a virus has less access unless its executed as root. worms have hit almost all platforms, even some marginally popular, through a variety of mechanisms. i cover this in some detail in a book i wrote which is shipping now ... "Defense and Detection Strategies against Internet Worms" (2003, artch house). </self pimping> i don't think we can make a direct correlation between quantifiable security and the prevalence of worms. after all, if there's only 10 identifiable security holes in a system but it accounts fo 90% of the internet landscape, of course it can be a useful worm target. counting security advisories or bugtraq topics isn't that good, either, since a lot of the difference can be accounted for by the different development models between closed source and open source projects. in short while i don't think there's much to the original gates claim, i don't think much of this followup makes sense, either. ___________________________ jose nazario, ph.d. [email protected] http://monkey.org/~jose/