Domain: mi2g.com
Stories and comments across the archive that link to mi2g.com.
Comments · 85
-
Requiem for the FUD// Please *don't* mod this up. It has already been done!
... some actual facts.
;)FreeBSD:
FreeBSD, Stealth-Growth Open Source Project (Jun 2004)
"FreeBSD has dramatically increased its market penetration over the last year."
Nearly 2.5 Million Active Sites running FreeBSD (Jun 2004)
"[FreeBSD] has secured a strong foothold with the hosting community and continues to grow, gaining over a million hostnames and half a million active sites since July 2003."
What's New in the FreeBSD Network Stack (Sep 2004)
"FreeBSD can now route 1Mpps on a 2.8GHz Xeon whilst Linux can't do much more than 100kpps."NetBSD:
NetBSD sets Internet2 Land Speed World Record (May 2004)
NetBSD again sets Internet2 Land Speed World Record (30 Sep 2004)OpenBSD:
OpenBSD Widens Its Scope (Nov 2004)
Review: OpenBSD 3.6 shows steady improvement (Nov 2004)*BSD in general:
Deep study: The world's safest computing environment (Nov 2004)
"The world's safest and most secure 24/7 online computing environment - operating system plus applications - is proving to be the Open Source platform of BSD (Berkeley Software Distribution) and the Mac OS X based on Darwin." ..and last but not least, we have the cutest mascot as well - undisputedly. ;)--
Being able to read *other people's* source code is a nice thing, not a 'fundamental freedom'. -
Requiem for the FUD// Please *don't* mod this up!
// The +1 readers have already seen it - and appreciated it. :)... facts are facts.
;)FreeBSD:
FreeBSD, Stealth-Growth Open Source Project (Jun 2004)
"FreeBSD has dramatically increased its market penetration over the last year."
Nearly 2.5 Million Active Sites running FreeBSD (Jun 2004)
"[FreeBSD] has secured a strong foothold with the hosting community and continues to grow, gaining over a million hostnames and half a million active sites since July 2003."
What's New in the FreeBSD Network Stack (Sep 2004)
"FreeBSD can now route 1Mpps on a 2.8GHz Xeon whilst Linux can't do much more than 100kpps."NetBSD:
NetBSD sets Internet2 Land Speed World Record (May 2004)
NetBSD again sets Internet2 Land Speed World Record (30 Sep 2004)OpenBSD:
OpenBSD Widens Its Scope (Nov 2004)
Review: OpenBSD 3.6 shows steady improvement (Nov 2004)*BSD in general:
Deep study: The world's safest computing environment (Nov 2004)
"The world's safest and most secure 24/7 online computing environment - operating system plus applications - is proving to be the Open Source platform of BSD (Berkeley Software Distribution) and the Mac OS X based on Darwin." ..and last but not least, we have the cutest mascot as well - undisputedly. ;)--
Being able to read *other people's* source code is a nice thing, not a 'fundamental freedom'. -
Requiem for the FUD// Please *don't* mod this up! The +1 readers have already seen it - and appreciated it
:) - a lot of times.
... facts are facts.
;)FreeBSD:
FreeBSD, Stealth-Growth Open Source Project (Jun 2004)
"FreeBSD has dramatically increased its market penetration over the last year."
Nearly 2.5 Million Active Sites running FreeBSD (Jun 2004)
"[FreeBSD] has secured a strong foothold with the hosting community and continues to grow, gaining over a million hostnames and half a million active sites since July 2003."
What's New in the FreeBSD Network Stack (Sep 2004)
"FreeBSD can now route 1Mpps on a 2.8GHz Xeon whilst Linux can't do much more than 100kpps."NetBSD:
NetBSD sets Internet2 Land Speed World Record (May 2004)
NetBSD again sets Internet2 Land Speed World Record (30 Sep 2004)OpenBSD:
OpenBSD Widens Its Scope (Nov 2004)
Review: OpenBSD 3.6 shows steady improvement (Nov 2004)*BSD in general:
Deep study: The world's safest computing environment (Nov 2004)
"The world's safest and most secure 24/7 online computing environment - operating system plus applications - is proving to be the Open Source platform of BSD (Berkeley Software Distribution) and the Mac OS X based on Darwin." ..and last but not least, we have the cutest mascot as well - undisputedly. ;)--
Being able to read *other people's* source code is a nice thing, not a 'fundamental freedom'. -
Requiem for the FUD... facts are facts.
;)FreeBSD:
FreeBSD, Stealth-Growth Open Source Project (Jun 2004)
"FreeBSD has dramatically increased its market penetration over the last year."
Nearly 2.5 Million Active Sites running FreeBSD (Jun 2004)
"[FreeBSD] has secured a strong foothold with the hosting community and continues to grow, gaining over a million hostnames and half a million active sites since July 2003."
What's New in the FreeBSD Network Stack (Sep 2004)
"FreeBSD can now route 1Mpps on a 2.8GHz Xeon whilst Linux can't do much more than 100kpps."NetBSD:
NetBSD sets Internet2 Land Speed World Record (May 2004)
NetBSD again sets Internet2 Land Speed World Record (30 Sep 2004)OpenBSD:
OpenBSD Widens Its Scope (Nov 2004)
Review: OpenBSD 3.6 shows steady improvement (Nov 2004)*BSD in general:
Deep study: The world's safest computing environment (Nov 2004)
"The world's safest and most secure 24/7 online computing environment - operating system plus applications - is proving to be the Open Source platform of BSD (Berkeley Software Distribution) and the Mac OS X based on Darwin." ..and last but not least, we have the cutest mascot as well - undisputedly. ;)--
Being able to read *other people's* source code is a nice thing, not a 'fundamental freedom'. -
Re:Hi. I'm Troy McClureHeh.. I'm sorry for Microsoft then.
;)FreeBSD:
FreeBSD, Stealth-Growth Open Source Project (Jun 2004)
"FreeBSD has dramatically increased its market penetration over the last year."
Nearly 2.5 Million Active Sites running FreeBSD (Jun 2004)
"[FreeBSD] has secured a strong foothold with the hosting community and continues to grow, gaining over a million hostnames and half a million active sites since July 2003."
What's New in the FreeBSD Network Stack (Sep 2004)
"FreeBSD can now route 1Mpps on a 2.8GHz Xeon whilst Linux can't do much more than 100kpps."NetBSD:
NetBSD sets Internet2 Land Speed World Record (May 2004)
NetBSD again sets Internet2 Land Speed World Record (30 Sep 2004)OpenBSD:
OpenBSD Widens Its Scope (Nov 2004)
Review: OpenBSD 3.6 shows steady improvement (Nov 2004)*BSD in general:
Deep study: The world's safest computing environment (Nov 2004)
"The world's safest and most secure 24/7 online computing environment - operating system plus applications - is proving to be the Open Source platform of BSD (Berkeley Software Distribution) and the Mac OS X based on Darwin." ..and last but not least, we have the cutest mascot as well - undisputedly. ;)--
Being able to read *other people's* source code is a nice thing, not a 'fundamental freedom'. -
Dispelling some more FUD... facts are facts.
;)FreeBSD:
FreeBSD, Stealth-Growth Open Source Project (Jun 2004)
"FreeBSD has dramatically increased its market penetration over the last year."
Nearly 2.5 Million Active Sites running FreeBSD (Jun 2004)
"[FreeBSD] has a secured a strong foothold with the hosting community and continues to grow, gaining over a million hostnames and half a million active sites since July 2003."
What's New in the FreeBSD Network Stack (Sep 2004)
"FreeBSD can now route 1Mpps on a 2.8GHz Xeon whilst Linux can't do much more than 100kpps."NetBSD:
NetBSD sets Internet2 Land Speed World Record (May 2004)
NetBSD again sets Internet2 Land Speed World Record (30 Sep 2004)OpenBSD:
OpenBSD Widens Its Scope (Nov 2004)
Review: OpenBSD 3.6 shows steady improvement (Nov 2004)*BSD in general:
Deep study: The world's safest computing environment (Nov 2004)
"The world's safest and most secure 24/7 online computing environment - operating system plus applications - is proving to be the Open Source platform of BSD (Berkeley Software Distribution) and the Mac OS X based on Darwin." ..and last but not least, we have the cutest mascot as well - undisputedly. ;) -
Requiem for the FUD... facts are facts.
;)FreeBSD:
FreeBSD, Stealth-Growth Open Source Project (Jun 2004)
"FreeBSD has dramatically increased its market penetration over the last year."
Nearly 2.5 Million Active Sites running FreeBSD (Jun 2004)
"[FreeBSD] has a secured a strong foothold with the hosting community and continues to grow, gaining over a million hostnames and half a million active sites since July 2003."
What's New in the FreeBSD Network Stack (Sep 2004)
"FreeBSD can now route 1Mpps on a 2.8GHz Xeon whilst Linux can't do much more than 100kpps."NetBSD:
NetBSD sets Internet2 Land Speed World Record (May 2004)
NetBSD again sets Internet2 Land Speed World Record (30 Sep 2004)OpenBSD:
OpenBSD Widens Its Scope (Nov 2004)
Review: OpenBSD 3.6 shows steady improvement (Nov 2004)*BSD in general:
Deep study: The world's safest computing environment (Nov 2004)
"The world's safest and most secure 24/7 online computing environment - operating system plus applications - is proving to be the Open Source platform of BSD (Berkeley Software Distribution) and the Mac OS X based on Darwin." ..and last but not least, we have the cutest mascot as well - undisputedly. ;) -
Requiem for the FUD... facts are facts.
;)FreeBSD:
FreeBSD, Stealth-Growth Open Source Project (Jun 2004)
"FreeBSD has dramatically increased its market penetration over the last year."
Nearly 2.5 Million Active Sites running FreeBSD (Jun 2004)
"[FreeBSD] has a secured a strong foothold with the hosting community and continues to grow, gaining over a million hostnames and half a million active sites since July 2003."
What's New in the FreeBSD Network Stack (Sep 2004)
"FreeBSD can now route 1Mpps on a 2.8GHz Xeon whilst Linux can't do much more than 100kpps."NetBSD:
NetBSD sets Internet2 Land Speed World Record (May 2004)
NetBSD again sets Internet2 Land Speed World Record (30 Sep 2004)OpenBSD:
OpenBSD Widens Its Scope (Nov 2004)
Review: OpenBSD 3.6 shows steady improvement (Nov 2004)*BSD in general:
Deep study: The world's safest computing environment (Nov 2004)
"The world's safest and most secure 24/7 online computing environment - operating system plus applications - is proving to be the Open Source platform of BSD (Berkeley Software Distribution) and the Mac OS X based on Darwin." ..and last but not least, we have the cutest mascot as well - undisputedly. ;) -
Requiem for the FUD... facts are facts.
;)FreeBSD:
FreeBSD, Stealth-Growth Open Source Project (Jun 2004)
"FreeBSD has dramatically increased its market penetration over the last year."
Nearly 2.5 Million Active Sites running FreeBSD (Jun 2004)
"[FreeBSD] has a secured a strong foothold with the hosting community and continues to grow, gaining over a million hostnames and half a million active sites since July 2003."
What's New in the FreeBSD Network Stack (Sep 2004)
"FreeBSD can now route 1Mpps on a 2.8GHz Xeon whilst Linux can't do much more than 100kpps."NetBSD:
NetBSD sets Internet2 Land Speed World Record (May 2004)
NetBSD again sets Internet2 Land Speed World Record (30 Sep 2004)OpenBSD:
OpenBSD Widens Its Scope (Nov 2004)
Review: OpenBSD 3.6 shows steady improvement (Nov 2004)*BSD in general:
Deep study: The world's safest computing environment (Nov 2004)
"The world's safest and most secure 24/7 online computing environment - operating system plus applications - is proving to be the Open Source platform of BSD (Berkeley Software Distribution) and the Mac OS X based on Darwin." ..and last but not least, we have the cutest mascot as well - undisputedly. ;)--
Being able to read *other people's* source code is a nice thing, not a 'fundamental freedom'. -
Requiem for the FUD... facts are facts.
;)FreeBSD:
FreeBSD, Stealth-Growth Open Source Project (Jun 2004)
"FreeBSD has dramatically increased its market penetration over the last year."
Nearly 2.5 Million Active Sites running FreeBSD (Jun 2004)
"[FreeBSD] has a secured a strong foothold with the hosting community and continues to grow, gaining over a million hostnames and half a million active sites since July 2003."
What's New in the FreeBSD Network Stack (Sep 2004)
"FreeBSD can now route 1Mpps on a 2.8GHz Xeon whilst Linux can't do much more than 100kpps."NetBSD:
NetBSD sets Internet2 Land Speed World Record (May 2004)
NetBSD again sets Internet2 Land Speed World Record (30 Sep 2004)OpenBSD:
OpenBSD Widens Its Scope (Nov 2004)
Review: OpenBSD 3.6 shows steady improvement (Nov 2004)*BSD in general:
Deep study: The world's safest computing environment (Nov 2004)
"The world's safest and most secure 24/7 online computing environment - operating system plus applications - is proving to be the Open Source platform of BSD (Berkeley Software Distribution) and the Mac OS X based on Darwin." ..and last but not least, we have the cutest mascot as well - undisputedly. ;)--
Being able to read *other people's* source code is a nice thing, not a 'fundamental freedom'. -
Requiem for the FUD... facts are facts.
;)FreeBSD:
FreeBSD, Stealth-Growth Open Source Project (Jun 2004)
"FreeBSD has dramatically increased its market penetration over the last year."
Nearly 2.5 Million Active Sites running FreeBSD (Jun 2004)
"[FreeBSD] has a secured a strong foothold with the hosting community and continues to grow, gaining over a million hostnames and half a million active sites since July 2003."
What's New in the FreeBSD Network Stack (Sep 2004)
"FreeBSD can now route 1Mpps on a 2.8GHz Xeon whilst Linux can't do much more than 100kpps."NetBSD:
NetBSD sets Internet2 Land Speed World Record (May 2004)
NetBSD again sets Internet2 Land Speed World Record (30 Sep 2004)OpenBSD:
OpenBSD Widens Its Scope (Nov 2004)
Review: OpenBSD 3.6 shows steady improvement (Nov 2004)*BSD in general:
Deep study: The world's safest computing environment (Nov 2004)
"The world's safest and most secure 24/7 online computing environment - operating system plus applications - is proving to be the Open Source platform of BSD (Berkeley Software Distribution) and the Mac OS X based on Darwin." ..and last but not least, we have the cutest mascot as well - undisputedly. ;)--
Being able to read *other people's* source code is a nice thing, not a 'fundamental freedom'. -
Requiem for the FUD... facts are facts.
;)FreeBSD:
FreeBSD, Stealth-Growth Open Source Project (Jun 2004)
"FreeBSD has dramatically increased its market penetration over the last year."
Nearly 2.5 Million Active Sites running FreeBSD (Jun 2004)
"[FreeBSD] has a secured a strong foothold with the hosting community and continues to grow, gaining over a million hostnames and half a million active sites since July 2003."
What's New in the FreeBSD Network Stack (Sep 2004)
"FreeBSD can now route 1Mpps on a 2.8GHz Xeon whilst Linux can't do much more than 100kpps."NetBSD:
NetBSD sets Internet2 Land Speed World Record (May 2004)
NetBSD again sets Internet2 Land Speed World Record (30 Sep 2004)OpenBSD:
OpenBSD Widens Its Scope (Nov 2004)
Review: OpenBSD 3.6 shows steady improvement (Nov 2004)*BSD in general:
Deep study: The world's safest computing environment
"The world's safest and most secure 24/7 online computing environment - operating system plus applications - is proving to be the Open Source platform of BSD (Berkeley Software Distribution) and the Mac OS X based on Darwin." ..and last but not least, we have the cutest mascot as well - undisputedly. ;)--
Being able to read *other people's* source code is a nice thing, not a 'fundamental freedom'. -
Before people go nuts...
...this study is talking about manual exploits, and says as much:
The study also reveals that Linux has become the most breached 24/7 online computing environment in terms of manual hacker attacks overall and accounts for 65.64% of all breaches recorded, with 154,846 successfully compromised Linux 24/7 online computers of all flavours.
This is likely because of the great number of Linux servers, and the wide variety of network services and ports open to the world on such servers.
And it does, in fact, make distinct reference to Windows malware (self-propagating worms, viruses, etc.):
Malware proliferation
The recent global malware epidemics have primarily targeted the Windows computing environment and have not caused any significant economic damage to environments running Open Source including Linux, BSD and Mac OS X. When taking the economic damage from malware into account over the last twelve months, including the impact of MyDoom, NetSky, SoBig, Klez and Sasser, Windows has become the most breached computing environment in the world accounting for most of the productivity losses associated with malware - virus, worm and trojan - proliferation. This is directly the result of very insignificant quantities of highly damaging mass-spreading malware being written for other computing environments like Linux, BSD and Mac OS X.
Also interesting:
For the record, neither mi2g Ltd nor the mi2g Intelligence Unit have a business relationship with Apple Computers and we do not own any shares in that corporation. Previously, the mi2g data for one month was considered to be too small a sample and not representative of the global environment within which different types of entities - micro, small, medium and large - exist. We have addressed those concerns in the new study. The critics were against the previous study which also came out in favour of Apple and BSD, because the entrenched supporters of Linux and Windows felt that mi2g was guilty of 'computing blasphemy'. In subsequent months, mi2g's reputation was damaged on search engines and bulletin boards. We would urge caution when reading negative commentary against mi2g, which may have been clandestinely funded, aided or abetted by a vendor or a special interest group.
There are a wide variety of reasons to expect that Mac OS X is a significantly more secure computing platform than Windows in a non-server/desktop setting; this study only further confirms that. -
Re:Fun and games with statistics
-
Gift-horse halitosisNone of us, I guess, has paid the 24 quid or whatever mi2g are asking for their report and can only speculate on its place on the credible to bogus scale.
But it is instructive to read some prior comment on mi2g, such as "Iraq will destroy us by computer" the experts screamed, or a more general index of mi2g myths, or a search for mi2g at NTK or even their own reasonably barking mad press releases.
I'm not uncomfortable with a finding that Linus boxes leak like sieves whilst windows boxes immitate Fort Knox; I'm by no means in security denial here. But I simply don't believe a word mi2g say.
-
Re:for the non-dutch
This would not possibly be the same mi2g as in according to mi2g 'MyDoom is now estimated to have caused $38.5 billion of economic damage worldwide so far' now would it?
That would be 40% of the 9/11 damages to copy a comparison also made in Dutch media. -
A Coordinated PR Offensive?
I came across this company, who claim in their FAQ:
"Which Operating Systems are most vulnerable to digital attacks?"
"Based on the information garnered through SIPS in August 2003 for twelve trailing months, Linux is the most breached operating system followed by Microsoft Windows."
"For the twelve trailing months as of September 2003, 59.2% of all overt digital attacks were on systems running Linux and 20.8% were on systems running Windows."
They define 'overt digital attacks' as active hacks conducted by a person or a group, as opposed to a virus spreading through a network...
So, is it a worldwide PR campaign, perhaps?
-
A Coordinated PR Offensive?
I came across this company, who claim in their FAQ:
"Which Operating Systems are most vulnerable to digital attacks?"
"Based on the information garnered through SIPS in August 2003 for twelve trailing months, Linux is the most breached operating system followed by Microsoft Windows."
"For the twelve trailing months as of September 2003, 59.2% of all overt digital attacks were on systems running Linux and 20.8% were on systems running Windows."
They define 'overt digital attacks' as active hacks conducted by a person or a group, as opposed to a virus spreading through a network...
So, is it a worldwide PR campaign, perhaps?
-
Here is the report ..
The report can be found Here but it looks like it costs around 29.38 ..What a brilliant way to get rid of criticism
.. -
Re:Yeah...They are not counting server boxes that have been hacked, but websites.
From MI2g website:
Do multiple website attacks resulting from a single system breach count
as one attack or many?
Mass website attacks are counted as multiple attacks because although there is a single
action on the part of the attacker, economic damage is always done to multiple victims.
So if a single ISP box gets hacked, they may count that as 100 linux sites hacked because of virtual hosting.
But even more important than their actual counting methods are where they get their data. Again, according to the same paper:
mi2g is principally reliant on data for SIPS and EVEDA from a number of sources:-
- Personal relationships at CEO, CIO, CISO level within the banking, insurance and
reinsurance industry in Europe, North America and Asia. We have been involved in
pioneering cyber liability insurance cover for Lloyd's of London syndicates which has
given us access to case history since the late 1990s. - Monitoring hacker bulletin boards and hacker activity. We have several white hat
hackers who we use for penetration testing and developing our bespoke security
architecture that feed digital risk information through to us on a continuous basis
including vulnerabilities, exploits and the latest serious attacks they are aware of. - We maintain anonymous communication channels with a large number of black hat
hacker groups.
So their highly informed executive manager friends seem to know when their linux systems get hacked versus their windows systems, they browse the web, looking at defacement sites and they converse with script kiddies via email. Umm, does anyone else see an issue with their data collection methods besides me?
If you don't yet, then let me give you a simple example. Let's say that I wanted to bias the results. Mmm ... it appears that all I have to do is deploy one linux box that is virtual hosting say 2,000 sites that noone visits. I leave some things in a very insecure mode and let some script kiddies know about it. Once its been "hacked", the script kiddie posts on a board or sends email to mi2g.com and their numbers move by 2,000 sites.
You can show me analyst reports by people like this all day long. In the end, this report bears no relation to what I see day to day in the real world. -
-
Wow that article is retarded
mi29 chairman D.K. Matai said.
That's probably one of the worst articles I've read from Slashdot lately. The "report" in question appears to be from British security company "mi29". First of all, that name is wrong their name is mi2g. Oh wait, THAT mi2g?
Sorry people, but I don't think they're reliable or trustworthy. They're nothing but fearmongering vultures from what I've seen of them. And as for the report? Well, it's not free, it costs 30 pounds.
So we're presented with declarations from a report of which we cannot check the methodology, by a firm who likes to regularly make pronouncements of doom that never happen. Should we believe it? Certainly not. We should simply suspend judgment for the simple reason that we lack critical information to judge its value.
-
Mi2gA few months ago Mi2g seemed to be of the opinion that Linux and other Unices were less vulnerable than Windows. Microsoft even complained about that...
And now it's the other way around?
-
looks like marketing to meI don't have the expertise to comment on the validity or invalidity of their report, but from a marketing point of view, this article is the perfect way to generate interest in their reports. This company has a varity of businesses, one of which is to sell reports. If you choose to buy the report, it comes with some pretty intersting terms and conditions..
mi2g disclaims all warranties as to the accuracy, completeness or adequacy of the information. mi2g shall have no liability for errors, omissions or inadequacies in the information intelligence offered or for interpretations thereof. mi2g disclaims itself of any sales lost or damages incurred to other parties as a result of this information.
Doesn't seem like this company is too confident in any of the claims made in these reports..
Their monthly intelligence has a quote that makes their "reseach methods" look shady:
The Monthly Intelligence analyses and collects data from over 7,000 hacker groups worldwide and provides detailed monthly and year-to-date information on:
Seems a little far fetched to me, I doubt many "hacker groups" are open to research companies doing data collection.
-
looks like marketing to meI don't have the expertise to comment on the validity or invalidity of their report, but from a marketing point of view, this article is the perfect way to generate interest in their reports. This company has a varity of businesses, one of which is to sell reports. If you choose to buy the report, it comes with some pretty intersting terms and conditions..
mi2g disclaims all warranties as to the accuracy, completeness or adequacy of the information. mi2g shall have no liability for errors, omissions or inadequacies in the information intelligence offered or for interpretations thereof. mi2g disclaims itself of any sales lost or damages incurred to other parties as a result of this information.
Doesn't seem like this company is too confident in any of the claims made in these reports..
Their monthly intelligence has a quote that makes their "reseach methods" look shady:
The Monthly Intelligence analyses and collects data from over 7,000 hacker groups worldwide and provides detailed monthly and year-to-date information on:
Seems a little far fetched to me, I doubt many "hacker groups" are open to research companies doing data collection.
-
looks like marketing to meI don't have the expertise to comment on the validity or invalidity of their report, but from a marketing point of view, this article is the perfect way to generate interest in their reports. This company has a varity of businesses, one of which is to sell reports. If you choose to buy the report, it comes with some pretty intersting terms and conditions..
mi2g disclaims all warranties as to the accuracy, completeness or adequacy of the information. mi2g shall have no liability for errors, omissions or inadequacies in the information intelligence offered or for interpretations thereof. mi2g disclaims itself of any sales lost or damages incurred to other parties as a result of this information.
Doesn't seem like this company is too confident in any of the claims made in these reports..
Their monthly intelligence has a quote that makes their "reseach methods" look shady:
The Monthly Intelligence analyses and collects data from over 7,000 hacker groups worldwide and provides detailed monthly and year-to-date information on:
Seems a little far fetched to me, I doubt many "hacker groups" are open to research companies doing data collection.
-
Only 30 pounds...
It only costs you 30 pounds to read the whole report here, so if you want to know the methodology, it will cost you. I guess that's better than Microsoft paying for the report...
-
Ubiquitousness doesn't explain MS vulnerabilitiesIf as many people tried as hard to find security holes in OSX or Linux, there'd be reports for those daily as well.
That's patently untrue. It's a well-known fact that Microsoft's security problems are not due to exposure alone.
Microsoft's development model is fundamentally flawed from a security perspective, because it squarely places featureset additions above security. The corporate culture at Microsoft is and always has been more about gaining marketshare than about anything else.
It seems that there are differences in security, above and beyond the monopoly domination Microsoft enjoys. How many ISPs use FreeBSD to run their servers? Hmm.. I wonder if there's more to it than just speed and the fact that FreeBSD is Open Source.
I'm not alone in my assesment. There's this security guru named Bruce Schneier. Perhaps his name has crossed your desktop at some point. He's contemplating getting a Mac, because he is tired of hassling with security problems on his Windows machines.
-
Re:Crossover?
Maybe if Linux people got it together, realized OS X is everything they've always wanted Linux and Unix to be, and got out of this dillusional world where it's "cool" to write a driver for your own printer and have a forever glitchy OS, not to mention one that's prone to hacks and virii, this would be a null point.
Now stop being a glution for punishment, and go buy a real computer with a real OS, and Quicktime. Sorry to be so rough on you guys, but you just need a good bitch smack from reality. Anywhoo, posting as AC to avoid having my mail flooded with defenders of the... whatever today's popular movement is.
WARNING: Anti-Linux/Unix Comment Posted. Begin mod-down to deny truth in 5.....4.....3.....2... -
Most Secure OS
According to this article the most secure OS were SCO Unix, Mac OS and Tru 64.
-
1) Stupid, stupid article. 2) Slashdot owns you?
Stupid, stupid article. No one knows how many attacks there are. The numbers are entirely nonsense. My guess is that whoever wrote that saw some way to make money by saying it.
mi2g is a company that makes more money if you think the sky is falling.
Many more stories like that, and Slashdot will stop being popular.
The article says, "But attacks on Windows/IIS systems have already dropped by 20 per cent on last year's figures, from 11,828 to 9,404."
My guess is that attacks occur about 20 times per hour for each IP address. That's how computers are rooted within 25 minutes of connecting to the Internet; there are continuous attacks to find weaknesses. That's how many I see, anyway.
That number cannot be the number of successful attacks, either. Most people who are rooted do not report that fact to anyone. Many Windows users would not even know they have been successfully attacked. How could they report it?
Change in subject: At the top of every article, it says, "The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way."
This sounds like you own your comments, doesn't it? However, the OSDN Terms of Service says at section "4. CONTENT", paragraph 6,
"In each such case, the submitting user grants OSDN the royalty-free, perpetual, irrevocable, non-exclusive and fully sublicensable right and license to use, reproduce, modify, adapt, publish, translate, create derivative works from, distribute, perform and display such Content (in whole or part) worldwide and/or to incorporate it in other works in any form, media, or technology now known or later developed, all subject to the terms of any applicable Open Source Initiative-approved license."
The contract is written in such a way as to appear that it has been made intentionally confusing. However, it looks like "comments are owned by whoever posted them" means that, yes, you own the intellectual property you created, but VA Software Corporation owns it too.
This appears similar to owning a car, but under the condition that someone else can use it at any time, and without notifying you. In any case, The Fine Print is misleading; it is not all of the fine print, although that line at the top of each story certainly encourages you to believe it is.
I don't know about Internet attacks, but we are seeing a rise in the number of sneaky contracts. This seems due to the presence of people with no technical knowledge at technically oriented companies. These people cannot contribute to the real work of the companies; all they can do is invent ways to abuse the customer.
EULA: I've been studying their methods, and I have a sneaky contract of my own. I agree to VA Software Corporation's sneaky contract if they agree to mine: At any time of my choosing, VA Software Corporation will give all managerial and financial control of the company to me. -
Re:mi2g
Oh I don't know, they don't seem to be all bad. http://www.mi2g.com/cgi/mi2g/press/speech171001.p
h p Makes you wonder when they signed on Microsoft as a client though... -
mi2gEvidentally, this story is a re-typing of the press release from "mi2g", so you might as well look at the original: Digital attacks on Open Source systems soar. It includes a bunch of pointers to pdfs of graphs of their data (none of which I can read because of some sort of "can't find colorspace cs8" error). But they don't appear to include any additional information, they're just graphs.
The source of the data is supposed to be the "mi2g SIPS database", about which they say:
The mi2g SIPS (Security Intelligence Products and Systems) database has information on over 6,000 hacker groups and maintains a record of over 60,000 individual hacking events since 1995. The SIPS intelligence citations include the 2002 Computer Security Institute (CSI) / Federal Bureau of Investigation (FBI) Computer Security Issues and Trends Survey [Vol. VIII, No. 1 - Spring 2002]
(Do you need me to toss in some editorializing about how this is evidentally a company that specializes in publishing alarmist press releases to encourage people to buy their products? Oh, and take a look at key clients... yup, includes Microsoft).
-
mi2gEvidentally, this story is a re-typing of the press release from "mi2g", so you might as well look at the original: Digital attacks on Open Source systems soar. It includes a bunch of pointers to pdfs of graphs of their data (none of which I can read because of some sort of "can't find colorspace cs8" error). But they don't appear to include any additional information, they're just graphs.
The source of the data is supposed to be the "mi2g SIPS database", about which they say:
The mi2g SIPS (Security Intelligence Products and Systems) database has information on over 6,000 hacker groups and maintains a record of over 60,000 individual hacking events since 1995. The SIPS intelligence citations include the 2002 Computer Security Institute (CSI) / Federal Bureau of Investigation (FBI) Computer Security Issues and Trends Survey [Vol. VIII, No. 1 - Spring 2002]
(Do you need me to toss in some editorializing about how this is evidentally a company that specializes in publishing alarmist press releases to encourage people to buy their products? Oh, and take a look at key clients... yup, includes Microsoft).
-
11,828 attacks for windows last yearThe article claims that the number of attacks on windows system last year were 11,828.
What counts as an attack? So worms don't count, or the number would be in the millins. Reported attacks? Those shouldn't count much because there is "little incentive for a company to report computer attacks.
Here's another story by the supposed source, but again, they don't at all define what they mean by "attack".
-
I use http://www.mi2g.com
I've used MI2G.com who has offices in London and the US. They've been very busy post-9/11 doing some 'hush-hush' type work, but they have a new security audit matrix that they are using with a number of government agencies that is getting pretty good reviews. They also build out secure systems for banks and financial hosues. I think they also have an office in India.
e-mail me if you want some more info on them.