Re: bill gates' claim about security vulnerabilities per LOC in Unix versus Windows

Jose Nazario <[email protected]>
Newsgroups gmane.comp.security.programming
Message-ID <[email protected]>
On Sun, 2 Nov 2003, Lucas Holt wrote:

> If Microsoft has such secure software, then why do these "worms"
> exploit only Microsoft products.  Sure one can argue that Microsoft is
> number one and therefore it would make sense to exploit windows on that
> basis to hit a larger target.  By now I would think someone would attack
> linux or Mac OS X just to prove it can be done.  The only linux worms i
> am aware of only attacked apache.  (there could be more)  Of course on a
> non windows system, a virus has less access unless its executed as root.

worms have hit almost all platforms, even some marginally popular, through
a variety of mechanisms. i cover this in some detail in a book i wrote
which is shipping now ... "Defense and Detection Strategies against
Internet Worms" (2003, artch house). </self pimping>

i don't think we can make a direct correlation between quantifiable
security and the prevalence of worms. after all, if there's only 10
identifiable security holes in a system but it accounts fo 90% of the
internet landscape, of course it can be a useful worm target.

counting security advisories or bugtraq topics isn't that good, either,
since a lot of the difference can be accounted for by the different
development models between closed source and open source projects.

in short while i don't think there's much to the original gates claim, i
don't think much of this followup makes sense, either.

___________________________
jose nazario, ph.d.			[email protected]
					http://monkey.org/~jose/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.