Slashdot Mirror


Microsoft or Apple - Who Is the Faster Patcher?

Amy Bennett writes "And the answer is... Microsoft. Researchers from the Swiss Federal Institute of Technology analyzed 658 high-risk and medium-risk vulnerabilities affecting Microsoft products and 738 affecting Apple. They measured how many times over the past six years the two vendors were able to have a patch available on the day a vulnerability became publicly known, which they call the 0-day patch rate. What they found: 'Apple was below 20 [unpatched vulnerabilities at disclosure] consistently before 2005,' said Stefan Frei, one of the researchers involved in the study. 'Since then, they are very often above. So if you have Apple and compare it to Microsoft, the number of unpatched vulnerabilities are higher at Apple.'"

11 of 252 comments (clear)

  1. Re:this is no surprise... by Yokaze · · Score: 2, Informative

    From the summary:
    > 658 [...] affecting Microsoft products and 738 affecting Apple

    --
    "Between strong and weak, between rich and poor [...], it is freedom which oppresses and the law which sets free"
  2. Re:Apple's shortcomings by truthsearch · · Score: 4, Informative

    Apple tells you what's fixed with every security update. Here's the document for the most recent: http://support.apple.com/kb/HT1249.

    It's specific enough for me, listing every application / library, impact, and description.

  3. Re:Apples to ... by CaptainPatent · · Score: 2, Informative

    Go ahead... say it:
    Orange

    --
    Well, back to rejecting software patent applications.
  4. Re:Well, duh... by Anonymous Coward · · Score: 5, Informative
    That's exactly right. Microsoft batch their updates once a month. Apple do it less regularly and less frequently, and they are frequently *unbelievably* slow to patch issues in the Free software they ship that's also in Linux or BSD distributions (trust me, I track this stuff for my employer.) God only knows how bad they are about patches in their own code. They didn't even manage to fix a typo in the Safari / win32 port EULA right first time.

    Personally as a certified Free software I'm rubbing my hands & looking forward to the Linux types who've switched for, basically, teh shiny. It's Freedom that counts folks, not features or functions or shiney... Freedom.

  5. meh by wizardforce · · Score: 3, Informative

    They measured how many times over the past six years the two vendors were able to have a patch available on the day a vulnerability became publicly known, which they call the 0-day patch rate
    yaah and how many security flaws have been sitting un-patched for months, years even at microsoft? let us take a look at how many security holes remain un-patched shall we?
    --
    Sigs are too short to say anything truly profound so read the above post instead.
  6. Where's the Beef? by 99BottlesOfBeerInMyF · · Score: 3, Informative

    So this is an article that doesn't give any answers to the question it poses and references a study presented at blackhat, but which has not yet been published and in fact whose presentation is not even online yet.

    Can't we at least wait until we have some sort of data to discuss before embarking on half-assed arguments about how relevant the data is and if the methodology is credible?

  7. Here's a link to the original research paper by sidney · · Score: 3, Informative
    There is of course a lot more information in the actual research paper.

    That link is to a browser view of the PDF at pdfmenot.com which caches the actual PDF, so the poor researcher's personal web site doesn't get hit too hard. You could download the original PDF from there if you really want to.

  8. Re:Look at it my way by Drakin020 · · Score: 2, Informative

    Dude that SP1 patch was not an official release for the public. More like a leak.

    The official release has worked great for everyone I know.

    Troll somewhere else please.

    --
    The greatest revenge in life is massive success.
  9. Re:Thats because M$ just has more 'features' by illumin8 · · Score: 2, Informative

    The only reason why MS is coming out on top is because they own the kitchen and cook their own numbers to order.
    Exactly. MS intentionally sits on vulnerabilities and doesn't announce them publicly until the patch is available. Apple, on the other hand, uses a lot of free and open-source software where full disclosure is considered important enough to notify all users through normal mailing lists, newsgroups, and other channels.

    This study is intentionally biased to make MS look good and Apple look bad. Which would you rather have, the blackhat broke into your network through an undisclosed MS hole that allows remote privilege escalation across the network (typical for MS products), or an open source library that you never use and is not exposed to any network facing service has a publicly announced vulnerability (which doesn't affect you personally) and is patched 6 months later by Apple?

    It's such a non-issue in the first place because OS X is UNIX and UNIX is fundamentally more secure than any Windows architecture based machine. But MS can keep buying all the studies in the world to try to prove to the PHB crowd that the sky isn't blue, it's green, and that water really isn't wet. It works in politics... tell a lie often enough and people start to believe it (there are WMDs in Iraq) so it must work for technology too (Windows is more secure than OS X)...
    --
    "When the president does it, that means it's not illegal." - Richard M. Nixon
  10. Re:Article Lacks Important Information by againjj · · Score: 1, Informative

    You mean that Apple was "below 20" and then got WORSE. Having more than 20 unpatched vulnerabilities is a bad thing compared to less than 20, not a good thing.

  11. Re:Well, duh... by SomeKDEUser · · Score: 2, Informative

    I call bullshit. digikam is a much better _GUI_ program than iPhoto. Better designed, less irritating, more powerful.

    I know the truth hurts, but in terms of easy-to-use power, MacOS was overtaken by KDE 3 years ago...