Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Windows beats Linux / Unix on vulnerabilities

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
Home » Discuss » DU Groups » Computers & Internet » Open Source and Free Software Group Donate to DU
 
Nomad559 Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jan-05-06 01:11 PM
Original message
Windows beats Linux / Unix on vulnerabilities
Windows beats Linux / Unix on vulnerabilities

It might not feel like it, but Windows suffered less security vulnerabilities than Linux and Unix during 2005.

Linux and Unix experienced more than three times as many reported security vulnerabilities than Windows, according to the mighty US Computer Emergency Readiness Team (CERT) annual year-end security index.

Windows experienced 812 reported operating system vulnerabilities for the period between January and December 2005, compared to 2,328 for Linux and Unix.
Refresh | 0 Recommendations Printer Friendly | Permalink | Reply | Top
WannaJumpMyScooter Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jan-05-06 03:46 PM
Response to Original message
1. Maybe for the core OS... but the main problems with
windoze is in the integrated MS apps, like Outlook and Excel.

IMHO.
Printer Friendly | Permalink | Reply | Top
 
RoyGBiv Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jan-05-06 08:30 PM
Response to Original message
2. Uh, yeahright ...

See the thing is, this is based on reported vulnerabilities. (Also worth mentioning is that this comparison is based on the single Windows OS contrasted against three distinct OS's, one of which has multiple variations.) Since Linux in particular is OpenSource, the security vulnerabilities are detected *and* patched at a much faster rate than those in proprietary OS's like Windows. In addition, Windows itself almost never reports flaws that are not deemed, by itself, as critical. OSS developers report every little thing. For example, I got an update today for an obscure little program I have on my system that had the ubiquitous buffer-overflow flaw. This is a security vulnerability, one deemed by most standards critical. Of course, the worst that could happen is that the program involved would crash, but that's still critical if I depend on it. And I'll note once again in case it was missed ... it was patched today.

Windows and its associated apps have severe security flaws that have been known for months, in some cases years, that have not even been addressed in work-arounds, much less fixed. The currently hot story about the problem with .wmf files has been a flaw since the inception of that file format, and it is only now even being discovered by the public at large.

This is the benefit of closed source to those who market it. It allows the developers to keep their secret flaws until they are in the exploitation phase, and so they can truthfully go to the public and say we have fewer "known" flaws than this other OS.
Printer Friendly | Permalink | Reply | Top
 
Commie Pinko Dirtbag Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jan-06-06 12:00 PM
Response to Original message
3. Some things for you:
Printer Friendly | Permalink | Reply | Top
 
RoyGBiv Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Jan-08-06 09:03 PM
Response to Original message
4. Another reality check ...
...

"The study is confusing and misleading. When you look at the list, the vulnerabilities are miscategorised," Mark Cox, consulting software engineer at Red Hat, told ZDNet UK.

"For example, Firefox is categorised as a Unix/Linux operating system flaw, but it runs just as well on a Windows platform. Apache and PHP also run just as well on both platforms. There are methodological flaws in the statistics," Cox claimed.

...

Secunia thought that the nature of the reported vulnerabilities also made it difficult to compare security on the platforms, as Linux/Unix researchers concentrate on vulnerabilities in local privilege separation, while Windows researchers look at possible remote vulnerabilities.

"Generally, many of the vulnerabilities in Linux/Unix based products are classified as local vulnerabilities, including privilege escalation, local denial of service and local exposure of sensitive data. These kind of vulnerabilities are not regarded as particularly critical, but Linux/Unix researchers tend to focus quite a lot on this category, probably because of Unix's long history of proper privilege separation. This has only recently become more relevant in Windows (NT, 2000, and XP), but many Windows researchers still focus more on remote issues."


http://news.zdnet.co.uk/software/linuxunix/0,39020390,39245889,00.htm
Printer Friendly | Permalink | Reply | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Fri Apr 26th 2024, 12:15 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » DU Groups » Computers & Internet » Open Source and Free Software Group Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC