Vista Security Claims Debunked
An anonymous reader writes "Apparently Microsoft still hasn't learned that counting vendor acknowledged vulnerabilities isn't a good way to establish the security of an OS. As an analysis of Microsoft's claims on Full Disclosure shows, we see that the methodology used was badly flawed. A bug in Firefox (not to mention emacs), counts as a flaw for Linux, while IE bugs get ignored on Vista's chart. Then we see that vulnerabilities aren't vulnerabilities when they're security-challenged features such as Vista's Teredo. Also, there's far too little consideration given to severity, given that it stoops to counting even extra access restrictions on a file in OSX to have something to show. In short, the original Microsoft analysis was good PR and poor research."
Given the previous FUD Microsoft has put out about Linux (235 patents? Which patents?), I'm not really surprised to see this.
Of course, if anyone should be counting browser flaws as OS flaws, it's MS. MS makes the case that they can't remove IE from the OS since it is integral to it working properly, yet doesn't count them on the vulnerability list.
Meanwhile, FF doesn't even have to come with a Linux distro, and a bug that compromises FF as an app is much less likely to compromise the OS as a whole.
Looks like more FUD to scare non technical people from "illegal" and "unsafe" Linux.
Very few people avoid IE, update their software, have a firewall or any security smarts
Vista updates by default. It is nicely built into the shutdown interface. By default you "update and shut down" if an update is available. Firewall is also built in and seems to be relatively well designed. Very honestly I am impressed with Vista's default security.
The rest of your post I agree with. For example will this help my sister-in-law who loads every toolbar and screensaver known to man? Nope. If a user downloads flaky spyware software, there isn't an OS that can help. But Vista truly is a step in the right direction for the majority of folks who just want to browse and email.
See my journal for slashdot ID's by year. Mine created in 2005. http://slashdot.org/journal/289875/slashdot-ids-by-year
Regardless of whether it does or does not the claims are as silly and irrelevant as the slashdot stories 'proving' that Linux is more secure.
The number of bugs is not relevant, it there is one bug the system is vulnerable. What matters is the window of vulnerability. The time between discovery of the bug by the bad guys and fixing it by the good guys.
UNIX used to be known for its insecurity. Richie and crew invented the buffer overrun bug, Tony Hoare was referring to this blunder in C when he gave his Turing Award lecture he brought up the fact that the first principle of ALGOL 60 had been security.
The perceived level of security of a system has much less to do with familiarity than any actual objective measure. None of the systems that are on the market today is built well enough for its supporters to start challenging others to this type of dick size measurement contest. Its silly and unhelpful.
Looking for an Information Security student project suggestion?
Try http://dotcrimeManifesto.com/
Any observer from a tech background would know that this would turn his results to shit, but he is;
- A Microsoft Employee
- A Blogger
so that never mattered anyway.Unfortunately they seem to be so obsessed with winning by FUDing and spinning that they end up making crap. This is a great disservice to the whole computer industry.
Engineering is the art of compromise.
Marketing is cheaper than R&D.
How are they obscure? You can't know much about security at all without knowing about people like insecure.org, SecuriTeam, or the Full-Disclosure mailing list. Or maybe you meant the author, Kristian Hermansen? They're a security researcher at Cisco, FYI. But even then, what does obscurity matter if their criticisms are valid? You could be an anonymous coward and make a valid point, after all (alas, that's merely a hypothetical because you do not).
Then you claim that the second report addressed all those issues. That's not at all true. Sure, it doesn't count Firefox bugs any more, but that's not the real problem with the study. The real problem is that counting vendor-acknowledged bugs isn't a security metric at all! That's right, it's not the least bit useful for giving either an academic or real-world measure of security. You can't rescue the original study from that flaw without redoing it and abandoning the original premise.
But I guess you wouldn't know that, because you don't know these "obscure" sites that people who know about computer security do. I mean, next thing you know, people will be citing virtual unknowns like Bruce Schneier as if they knew anything about security! Or maybe Fyodor, I bet he doesn't know a damn thing about networking. What did he ever do? Make up that silly fake application they used as a "hacking" tool in the Matrix movies? [/sarcasm]
This means simply that Microsoft will generally pour just enough resources into a product to beat the competition and dominate the marketplace. We saw that with the browser war. When it had to overtake Netscape it came up with a good product. After it killed Netscape, and there was practically no other comparable browser, resources were taken off the browser product because it was good enough and there was no sense whatsoever in improving it.
We saw it with the IDE's. When Microsoft had to compete with Borland {Borland Pascal; Borland C/C++} it came up with the 'Visual' IDE. Visual C, Visual Fortran. It was a good IDE, and it won against Borland. After that ... it languished. Now ... now that we're seeing the Eclipse IDE and SUN's IDE ... suddenly Microsoft floors the accelerator again.
The same holds for the Operating System itself. Windows was systematically tailored to capture the eye of consumers and businesses, which it did very well. Never mind that the internals were {and still are} cludgy. What the user sees is the user-interface; that's what sells. Security flaws? Well ... as long as there is no competitor to which people can switch while retaining their investment in software and training ... security flaws aren't a show-stopper. Getting their own stuff to work was {previous Windows version have so many tightly coupled components that you never knew what would break next when you changed or added anything}, and that's why Jim Allchin very sensibly steered towards a properly engineered Windows. Vista in other words.
Given that we're seeing Linux, OS-X, and Open Solaris competing in more or less the same market we also saw an increased effort from Microsoft to tart up the user interface. Those transparant windows thingies.
This is something fundamental you have to understand about Microsoft. They are calculating folk, and never ever were trailblazers. Tail-light chasers, yes, but never trailblazers. 'Good Enough' is their goal, and their yardstick is ... the competition. Why? Because to Microsoft 'Good Enough' means 'Good enough to win in the marketplace and bring in revenue'. That's how Microsoft became so rich.
Such straight forward conclusions are impossible to make. Based on the following points.
- If many people are analysing code, you will find more bugs. If you don't review your code (or for example, don't have peer review - which closed source often lacks.) Then no bugs at all will be discovered.
- The existing number of unfound bugs is related to the number of discovered bugs. Well no not really: The number of found bugs is actually related to how long and how many researchers have been testing and actively looking for the bugs and second to that is how buggy the software is. I can assign a team of one researcher with no experience and they'll never find any bugs in the poorest of software.
- A difficult and obscure to exploit bug (one that requires a perfect storm of conditions) is as important as a bug that is easily exploitable(e.g. drive by downloads). Also with that: Bugs that bring down the whole system versus bugs that only fail a single service.(E.g. blue screen versus failing to display a JPG correctly.)
- Differences in reporting models: Total lack of transparency versus an open forum. E.g. Microsoft vs Linux reporting. You can only compare reporting from the same kind of reporting models. E.g. You can compare kHTML versus Mozilla (as they are both open and have similar review structures), but not Windows vs BSD (the dissimilar reviews allow misrepresentation via favourable skews and different classification paradigms.
You haven't read an annual company report recently, or ever for that matter?
Even in sdoftware - or pharmaceutical companies where one would assume that a lot is spent for research the R&D budget is usual ~18% (which varies, of course) while sales and marketing usually eats away approx. half of the costs.
Sales, marketing and distribution is horrendously expensive and gets a far bigger chunk of the budget then R&D.
This is a generalisation, of course, but true for the vast majority of companies.
ich bin der musikant
mit taschenrechner in der hand
kraftwerk
The point is simply that number of disclosed bugs is not a valid comparison. It matters not if he "did his best".
"The numbers" would certainly look very different if Microsoft adopted the methodology used by most open source projects of fully disclosing every bug. Or if open source projects mirrored Microsoft's practices. It is very well known that Microsoft does NOT fully disclose all bugs and many cumulative patches silently fix MANY problems. The severity of bugs is also classified very differently.
You are right about one thing, it is all a numbers game. But you are WRONG that it means anything, even that Microsoft is improving. It means NOTHING. Nothing at all. It's only a numbers game. Even if someone else games the numbers differently and Linux-based systems look better, it still means nothing to compare numbers of bugs when very different philosophies and practices govern which bugs are fully disclosed and how their severities are rated.
PJRC: Electronic Projects, 8051 Microcontroller Tools
Fixed that for you.
-- "I never gave these stories much credence." - HAL 9000