Slashdot Mirror


The Annual US-CERT FUD Festival

Joe Barr writes "Joe Brockmeier and I have teamed up in a story on NewsForge to point out how the mainstream and trade press misrepresent the annual summary of vulnerabilities from US-CERT. They're doing it again this year to make it appear as if it is more secure than UNIX/Linux. Pamela Jones did a similar report at Groklaw over the weekend." From the article: "One figure represents the vulnerabilities found in Windows operating systems: XP, NT, 98, and so on. The other represents a total figure not just for Solaris, AIX, HP-UX, the BSDs, and Linux, but for a hundred different versions of Linux. The sum of all the unique vulnerabilities from all the Linux distros does not equate to the sum of vulnerabilities in any single Linux distro, and one could say the same about the various versions of Windows. That's why it is a completely meaningless exercise to discuss those totals as if they present an accurate picture of the relative security of Windows and Linux. " We've reported on the US-CERT list already this year. NewsForge is a sister site to Slashdot.org, both of whom are owned by OSTG.

11 of 152 comments (clear)

  1. Should Compare A Single Version Of Windows Too by Anonymous Coward · · Score: 5, Insightful

    It's equally unfair to lump Windows 98, NT, 2000, XP all together. They could be looked at as different "distros" of Windows. Should pick the best or latest OS from each group with the least vulnerabilities to compare.

  2. Skewed? Oh yeah... by fak3r · · Score: 4, Interesting

    Considering Linux is a Kernel, to say there were 1000s of bugs again Linux is silly. Let's see how many were against the Linux kernel vs all the userland apps that don't touch anything system level. Now I'll admit bugs show up, and I think that's Open Source's strength; there's constantly ppl combing over the code finding f'd up stuff that no one would think to look at. This is only achieved through constant gazing at the source code, whereas with Windows a bug is usually found out after it's a vuln. Also, I'm happy that MS patched the issue so quickly, even if they were beaten to the punch, perhaps they'll take things (security) more seriously now that they're pushing 'trusted computing'. Not that I care that much, I'm sold on Linux, OS X on the desk and freeBSD on the server, but I did play with ReactOS the other night, and see a future for x-Windows folks who don't want to lose Windows compat when XP support goes away...

  3. The numbers are unimportant by Billosaur · · Score: 4, Insightful

    Shouldn't we be asking the more pertinent question: why do all the various operating systems have so many vulnerabilities? When it comes to such things, this shouldn't be a competition. OS builders should be striving for zero tolerance to vulnerabilities and there shouldn't be an quibbling over the number that exist.

    --
    GetOuttaMySpace - The Anti-Social Network
  4. Patch Time by ndtechnologies · · Score: 4, Insightful

    Good point and I'd like to add, What about the time length between when vulnerabilities are found, and then patched? Surely, they thought about that. Linux and Unix can continue to have more "reported" vulnerabilities than Windows, but if they are patched faster than Windows, doesn't that count for something?

    --
    I have nothing clever to put here...
  5. Take a deep breath and count to ten... by pieterh · · Score: 4, Insightful

    They're doing it again this year to make it appear as if it is more secure than UNIX/Linux.

    What is "it"? Slight tinge of paranoia here, maybe?

    Let's review the score here:

      - It does not matter what material is published, the fact of the matter is that every Windows PC in the world regularly has visible and non-trivial security issues, while on Linux and OS/X these issues are generally theoretical.

      - People's perceptions of Windows are very simple: it's a piece of crap that they use because it came with the box and everyone else uses it.

      - The relative security of Windows vs. the World is not a deciding factor in most people's use of Windows. It's largely a captive, neutered market.

      - For people who actually do care, no amount of statistics can change the visible and perceived situation. When I choose to ban Windows in my company, it's not because I read some website or article. It's because I'm sick and tired of removing spyware from people's PCs.

    Complaining about these statistics is to give them credibility. Those who chose on the basis of security will ignore this data, and those who chose on other criteria won't care about this data.

  6. Take what the CERT says with a grain of salt... by dpmccoy · · Score: 5, Insightful

    I'm an automation officer in the U.S. Army, and I know for a fact that we're full of Microsoft shills and contractors with Microsoft loyalties. We don't employ Unix/Linux in an enterprise manner; the government sold its soul to Microsoft years ago. Unix is used on some Army tactical platforms, though. Food for thought.

  7. Re:Downright Disingenuous by User+956 · · Score: 4, Informative

    The act of contrasting the vulnerabilities found in the few Windows operating systems with the vulnerabilities found in hundreds of Linux/Unix is bad enough, but when you consider that the Unix/Linux list contains duplicate items, it becomes positively shameful.

    It looks like we both posted at the same time. At any rate, you have a point to a certain degree. My post here shows that if you go through the list and subtract out all the items with "updated" after them, Subtract OSX and Solaris, the Linux/Unix group category is about par with windows, not 3x worse.

    Whether "different" OSes should be lumped together is another discussion entirely (how "different" are they if they have the same kernel?)

    --
    The theory of relativity doesn't work right in Arkansas.
  8. From the article.... anti-FUD stats by CodeShark · · Score: 5, Informative
    Not intending to "karma whore" here, but look at the stats from an already done analysis:
    • 22 Technical Cyber Security Alerts were issued in 2005
      • 11 of those alerts were for Windows platforms
      • 3 were for Oracle products
      • 2 were for Cisco products
      • 1 was for Mac OS X
      • None were for Linux
      , and secondarily look at this quote
    • "Here's more of the same. US-CERT's list of current vulnerabilities contains a total of 11 vulnerabilities, six of which mention Windows by name, and none of which mentions Linux.

    Folks, as other /. posters have already discussed better than I can, most of the supposed Linux bugs are either duplicates or in user- space software. That would be akin to saying a Firefox browser vulnerability is a Windows OS security problem,as opposed to an underlying OS vulnerability that would affect any and all software on the platform.
    --
    ...Open Source isn't the only answer -- but it's almost always a better value than the alternatives...
  9. My Own Research by vjmurphy · · Score: 4, Funny

    Using the patent-pending method of determining worth by comparing terms plugged into Google, I get the following:

    Search for "Windows Bugs": 45,800
    Search for "Linux Bugs": 23,400
    Search for "Bunny Bugs": 31,100

    From this method, I can determine that I should NOT watch Looney Tunes cartoons on my Windows Media Center PC. Or drink while posting.

    --
    Vincent J. Murphy
    Spandex Justice
  10. Re:Downright Disingenuous by MindStalker · · Score: 4, Insightful

    Whats worse is the fact that a POP3 Client Buffer Overflow on Windows would not be included at all as one doesn't ship with Windows. Linux distros generally ship with thousands of clients and servers while Windows ships with the bare minimum. To do a true security comparion you would have to compare either just kernel exploits with OS exploits, then compare all popular software for windows with all popular software for Linux side by side in a catagory basis (POP3 clients being a catagory)

  11. FALSE. by WindBourne · · Score: 4, Informative
    Umm, I looked at the list and they weren't counting the same vulnerability multiple times.

    Very false. just look for Larry Wall Perl Insecure Temporary File Creation (Updated). Three instances of the exact same item. And only in *nix even though ActiveState perl for Windows had the same issue. So, there are LOTS of issue with this report. Cert is more SNAFU, than not.

    --
    I prefer the "u" in honour as it seems to be missing these days.