Please support our Tech Talk advertiser:
Aug 21st, 2007, 6:23 am
Jeff Jones is a Strategy Director in the Microsoft Security Technology Unit, part of the team trying to make Microsoft products more secure, poor guy. No surprise that he publishes a vulnerability report on his Microsoft TechNet hosted Security Blog which always seems to suggest that Microsoft Windows is far more secure than competing operating systems from Linux vendors. What is slightly surprising, however, is that this is no died in the wool Windows guy but someone who first tasted Linux running a P66 SLS machine with end-to-end tunneling to internal office Sun servers, running X as his GUI and using an X-redirector across the tunnel. This is someone who has done kernel development on Trusted Xenix. This is a guy who knows a bit more about Linux than your average Windows OS developer.
The blog in question carries a certain amount of weight with the media courtesy of being a TechNet published one, and given the position of the poster in question. “Looking at Security from All Angles” the blog banner claims, continuing “Security is not simple, so we should try not to simplify it to the point of uselessness.”
Can’t argue with that, but I sure can argue with the conclusion drawn from the colorful graphs used to simply the security argument that Windows is hugely more secure than assorted Linux distros. The assumption is based upon research data concerning vulnerabilities that required patching, or to be absolutely precise after checking the methodologies statement handily published by Jeff at a completely different site, that had actually been patched by the vendor.
I quote “The vulnerabilities included in the analysis only include those vulnerabilities for which the vendor has confirmed applicability, typically via a security advisory or patch notice. The analysis here does not include publicly disclosed vulnerabilities during the period that have not yet been fixed by the vendor.” So, let’s get this straight, that is vulnerabilities that have been patched by the vendor, not zero-day flaws or vulnerabilities that are known about but not officially confirmed via advisory no matter how long in the tooth, just the ones that the vendor has fixed.
Secunia publishes independent reports of vulnerabilities listed by both vendor and product, as well as keeping historical archives of the same. Which makes for very interesting reading, and brings a slightly different perspective to the security picture being painted.
Take XP Pro, for example, which Secunia shows has 29 Secunia advisories yet to be patched, that’s 15% of the total. Or how about Windows Server 2003 Standard Edition with an 8% unpatched rating, equating to 11 of 135 advisories? Compare this to the product flagged as being most insecure according to the Microsoft OS Vulnerability Scorecard report, Red Hat Enterprise Linux 4 Workstation. Secunia shows 311 advisories being raised since 2005, but none of them remain unpatched.
This would tend to suggest to me that Red Hat is actually more secure than Windows, if we want to follow the advice not to simplify security to the point uselessness, because the ability and willingness of a vendor to quickly fix flaws when found has to be factored into any serious look at the security argument. Indeed, vendor response times are key when everyone agrees that it is all but impossible to write 100% secure code. Getting patches out to the user is the real metric of security, and ignoring those vulnerabilities which have yet to be so patched reduces the original report to being nothing more than FUD.
By displaying graphs that show Windows products in the less than 50 zone, while Apple, Novell, Red Hat and Ubuntu all drift upwards of 100 is nothing short of misleading.
And that is the real problem that I have with this vulnerability scorecard, if you take the time to read between the lines and delve a little deeper into what is being reported you discover that what it is actually saying is that Linux vendors are more efficient (although you might substitute the word ‘honest’ if you prefer) than Microsoft when it comes to announcing flaws and actually fixing them. What it reveals to me is how slow, comparatively speaking, Microsoft is at releasing patches.
The truth is that every OS will suffer from security flaws; all that matters in the end is how those flaws are dealt with and how quickly the end user is protected from the exploits they enable. Let me state here that I am no Linux fanboy (I write a security column published at Microsoft.com if proof were needed of that) but rather an unbiased commentator on IT security issues. However, at the end of the day I have to say that from where I am sitting the true vulnerability scorecard should read:
Linux 1, Microsoft 0
The blog in question carries a certain amount of weight with the media courtesy of being a TechNet published one, and given the position of the poster in question. “Looking at Security from All Angles” the blog banner claims, continuing “Security is not simple, so we should try not to simplify it to the point of uselessness.”
Can’t argue with that, but I sure can argue with the conclusion drawn from the colorful graphs used to simply the security argument that Windows is hugely more secure than assorted Linux distros. The assumption is based upon research data concerning vulnerabilities that required patching, or to be absolutely precise after checking the methodologies statement handily published by Jeff at a completely different site, that had actually been patched by the vendor.
I quote “The vulnerabilities included in the analysis only include those vulnerabilities for which the vendor has confirmed applicability, typically via a security advisory or patch notice. The analysis here does not include publicly disclosed vulnerabilities during the period that have not yet been fixed by the vendor.” So, let’s get this straight, that is vulnerabilities that have been patched by the vendor, not zero-day flaws or vulnerabilities that are known about but not officially confirmed via advisory no matter how long in the tooth, just the ones that the vendor has fixed.
Secunia publishes independent reports of vulnerabilities listed by both vendor and product, as well as keeping historical archives of the same. Which makes for very interesting reading, and brings a slightly different perspective to the security picture being painted.
Take XP Pro, for example, which Secunia shows has 29 Secunia advisories yet to be patched, that’s 15% of the total. Or how about Windows Server 2003 Standard Edition with an 8% unpatched rating, equating to 11 of 135 advisories? Compare this to the product flagged as being most insecure according to the Microsoft OS Vulnerability Scorecard report, Red Hat Enterprise Linux 4 Workstation. Secunia shows 311 advisories being raised since 2005, but none of them remain unpatched.
This would tend to suggest to me that Red Hat is actually more secure than Windows, if we want to follow the advice not to simplify security to the point uselessness, because the ability and willingness of a vendor to quickly fix flaws when found has to be factored into any serious look at the security argument. Indeed, vendor response times are key when everyone agrees that it is all but impossible to write 100% secure code. Getting patches out to the user is the real metric of security, and ignoring those vulnerabilities which have yet to be so patched reduces the original report to being nothing more than FUD.
By displaying graphs that show Windows products in the less than 50 zone, while Apple, Novell, Red Hat and Ubuntu all drift upwards of 100 is nothing short of misleading.
And that is the real problem that I have with this vulnerability scorecard, if you take the time to read between the lines and delve a little deeper into what is being reported you discover that what it is actually saying is that Linux vendors are more efficient (although you might substitute the word ‘honest’ if you prefer) than Microsoft when it comes to announcing flaws and actually fixing them. What it reveals to me is how slow, comparatively speaking, Microsoft is at releasing patches.
The truth is that every OS will suffer from security flaws; all that matters in the end is how those flaws are dealt with and how quickly the end user is protected from the exploits they enable. Let me state here that I am no Linux fanboy (I write a security column published at Microsoft.com if proof were needed of that) but rather an unbiased commentator on IT security issues. However, at the end of the day I have to say that from where I am sitting the true vulnerability scorecard should read:
Linux 1, Microsoft 0
This blog entry was written by Davey Winder, staff writer aka happygeek. It has received 4,628 views, 4 comments, and 54 linkbacks. 1 voter has rated this entry 5 out of 5 stars. It was promoted to featured status Aug 21st, 2007.
•
•
•
•
advertising apple browser business crime data development email facebook firefox gaming google hacking hardware ibm internet iphone ipod law legal linux malware microsoft mobile mozilla news novell office open source operating os privacy red hat research search security software spam survey system technology trojan ubuntu virus vista web windows xp yahoo youtube
All Recent Tags Comments (Newest First)
docsharp01 | Newbie Poster | 5 Days Ago
•
•
•
•
Microsoft is ok, but I prefer Linux instead.
http://www.1-satellite-tv-facts.com
http://www.1-satellite-tv-facts.com/Direct-TV.html
http://www.1-satellite-tv-facts.com/Dish-Network.html
http://www.1-satellite-tv-facts.com/...ite-Radio.html
http://www.1-satellite-tv-facts.com/...t-Service.html
http://www.1-satellite-tv-facts.com/Satellite-DSL.html
http://www.1-satellite-tv-facts.com/...-Internet.html
http://www.1-satellite-tv-facts.com/VoIP.html
http://www.1-satellite-tv-facts.com/Phone-Systems.html
http://www.1-satellite-tv-facts.com/...-Programs.html
http://www.1-satellite-tv-facts.com
http://www.1-satellite-tv-facts.com/Direct-TV.html
http://www.1-satellite-tv-facts.com/Dish-Network.html
http://www.1-satellite-tv-facts.com/...ite-Radio.html
http://www.1-satellite-tv-facts.com/...t-Service.html
http://www.1-satellite-tv-facts.com/Satellite-DSL.html
http://www.1-satellite-tv-facts.com/...-Internet.html
http://www.1-satellite-tv-facts.com/VoIP.html
http://www.1-satellite-tv-facts.com/Phone-Systems.html
http://www.1-satellite-tv-facts.com/...-Programs.html
Infarction | Battle Programmer | Aug 22nd, 2007
•
•
•
•
> In fact the majority of flaws in Windows itself are not known before Microsoft themselves discover them and release a patch.
Also, at one point, most exploits were reverse-engineered from the patches, and effected between the time the patch was released and the time users actually got around to installing it (which is why it takes longer now to get patches out, what with obfuscating the binaries etc...). But it's MSFT's fault, as always...
Also, at one point, most exploits were reverse-engineered from the patches, and effected between the time the patch was released and the time users actually got around to installing it (which is why it takes longer now to get patches out, what with obfuscating the binaries etc...). But it's MSFT's fault, as always...
jwenting | duckman | Aug 21st, 2007
•
•
•
•
yes it is. It is certainly true that the majority of compromised systems in real numbers run Windows, but it's just as true that the majority of compromised systems as a percentage of installed base are running Linux (and to a lesser degree other Unix flavours).
What Davey of course wants you to believe is that Linux vendors are faster at fixing flaws than is Microsoft, something that's patently untrue, that every compromised Windows machine is due to something Microsoft failed to patch while every compromised Linux machine is due to negligence of the operator.
Neither is true, not to any degree whatsoever.
In fact the majority of flaws in Windows itself are not known before Microsoft themselves discover them and release a patch.
The same is to some extent true for Linux as well, though most Linux vendors don't bother looking for or fixing flaws, instead relying on the goodwill of their users to do it for them.
What Davey of course wants you to believe is that Linux vendors are faster at fixing flaws than is Microsoft, something that's patently untrue, that every compromised Windows machine is due to something Microsoft failed to patch while every compromised Linux machine is due to negligence of the operator.
Neither is true, not to any degree whatsoever.
In fact the majority of flaws in Windows itself are not known before Microsoft themselves discover them and release a patch.
The same is to some extent true for Linux as well, though most Linux vendors don't bother looking for or fixing flaws, instead relying on the goodwill of their users to do it for them.
TaoistTotty | Light Poster | Aug 21st, 2007
•
•
•
•
Is this not the way will all polls.
If any company make a poll public they usually show they are the best at whatever. Why release one that shows you are the worse.
It is all in how the questions are asked and analysed.
It brings to mind the phrase 'there are lies and there are statistics'.
If any company make a poll public they usually show they are the best at whatever. Why release one that shows you are the worse.
It is all in how the questions are asked and analysed.
It brings to mind the phrase 'there are lies and there are statistics'.
Post Comment
•
•
•
•
Only community members can start a blog or comment on blog entries. You must register or log in to contribute.
•
•
•
•
•
•
•
•
DaniWeb Tech Talk Marketplace
Related Blog Entries
- Viacom defends itself over YouTube data log disclosure (23 Hours Ago)
- Apple slow to patch iPhone security holes (1 Day Ago)
- Microsoft 'Equipt' to Battle Free Software (1 Day Ago)
- 12,000 laptops lost in US airports EVERY WEEK (2 Days Ago)
- Ballmer Again Chomping At The Bit for Yahoo (3 Days Ago)
- Apple iPhone 3G creates shortage of flash memory chips (3 Days Ago)
- Seeing double, twice, with Matrox M-Series QuadHead GPU (4 Days Ago)
- Good-bye Windows XP, Hello Open Source? (4 Days Ago)
- Tux, Please Pass The Packets. (5 Days Ago)
- Googlebot gets to grip with Flash (5 Days Ago)
Related Forum Threads
- What's better? Windows 2000 Server or Linux Server? (Windows Servers and IIS)
- Microsoft - sort it out (rant) (Software Developers' Lounge)
- Project to design a internet security plan (Network Security)
- Linux Security Scanner (*nix Software)
- Windows vs. Linux (Linux Users Lounge)
- Linux vs. Microsoft Windows (Linux Users Lounge)
- Microsoft,What did you say about Security Issues? (Viruses, Spyware and other Nasties)
- What is Your Opinion About Microsofts OS (Windows Software)
Featured Entry