On CBSSports.com: Today’s Maxim Spin Girl
BNET Business Network:
BNET
TechRepublic
ZDNet

By Robert Lemos
Posted on ZDNet News: Aug 13, 2004 7:47:00 PM

Microsoft has been waiting for security researchers to say that its Windows operating system has a lower total cost of ownership. One finally has, but that's not good news.

On Friday, David Aitel, a noted security professional and managing director of vulnerability assessment firm Immunity, published a paper stating that "owning" a computer--hacker-speak for compromising a system--is easier if the target computer runs Windows. While couched in puns and jokes, the paper takes a serious stance on the security of Windows compared with modern Linux, Aitel said.

"We are having some fun with it, but the underlying data and conclusions are real," he said.

The paper, titled "Microsoft Windows: A lower Total Cost of 0wnership," mocks other, typically Microsoft-funded, research, such as a study done by IDC that maintains Windows costs less to implement in four out of five corporate applications. Another such study, released by Forrester, found that a particular measure of the threat of vulnerabilities was higher for Linux than for Windows--but the data used by the study was broadly questioned.

The Aitel paper marks the first time that a security professional with hands-on experience of hacking both Linux and Windows systems has weighed in on the issue.

His conclusion: The security of Windows computers is easier to breach than modern Linux computers, despite more than two years of work by Microsoft to secure its operating system under its Trustworthy Computing initiative. Microsoft declined to comment on the paper.

The report has very little supporting data, however, making it less of a challenge to Microsoft and more of another voice in the long-running debate between the two operating-system camps.

Based on their tentative data, Immunity's researchers found that their average time to find a flaw in the Red Hat-sponsored Fedora Core 2 distribution of Linux was about six days--twice as long on average as it took to find previously unknown Windows vulnerabilities. Several factors affect that time, including better tools for finding flaws in Windows systems, better kernel-level defenses in Linux, and more known points in Windows to execute attack code, the researchers noted.

Microsoft recently released a massive security update for Windows XP, a reaction to the massive spread of the MSBlast, or Blaster, worm a year ago, but that still will not close most of the holes until a major security feature in PC processors is more widely available, Aitel said. That feature, known as the nonexecutable flag or write-XOR-execute bit, allows processors to prevent attackers from executing code. However, only Advanced Micro Devices has introduced the technology, which it calls enhanced virus protection (EVP), into its mainstream processors.

Adding to the security issues he has with Windows, Aitel pointed out that, while getting customers to patch is a problem for both platforms, Linux patching utilities update a wide variety of applications, not just the core operating system, as is typical of Windows fixes.

  • Talkback
  • Most Recent of 73 Talkback(s)
Mac point of view
I'm just a user, not an admin, and probably fit the zealot
label, but I am continually amazed how little Windows
users demand of Microsoft. It took them 10 years to get
past 8 character fi... (Read the rest)
Posted by: sdwood Posted on: 08/22/04 You are currently: Logged In | Log out
this is nice and all....but where's the link? Monkey_MCSE   | 08/13/04
This is a white paper dhk   | 08/14/04
Talk about your misleading titles... Michael Kelly   | 08/13/04
Well, it's a staple for ZDNet.. Jeff Spicoli   | 08/13/04
SP2 georgep_z   | 08/13/04
Nope, you missed the point TechDiva_z   | 08/13/04
Don't any of you understand what constitutes data? dhk   | 08/14/04
Without data the whitepaper is opinion, not fact balsover   | 08/15/04
Linux is not for everyone -- so why are you worried about this paper? dhk   | 08/15/04
Here is the a link to the paper. toadlife   | 08/13/04
I think you missed the point dhk   | 08/14/04
Allow me to break it down for you toadlife   | 08/14/04
You just don't get it dhk   | 08/14/04
You take the paper too seriously toadlife   | 08/14/04
The paper is serious dhk   | 08/15/04
You might have a few misconceptions about me toadlife   | 08/15/04
My conceptions can only be based on what you say dhk   | 08/15/04
The servers weren't patched toadlife   | 08/15/04
I've just rechecked CERT & others -- you're incorrect dhk   | 08/15/04
I'm completely and utterly dumbfounded. toadlife   | 08/15/04
I believe you are dumbfounded dhk   | 08/16/04
Disagree re OS X Fred Fredrickson   | 08/15/04
You misunderstood the data in the table dhk   | 08/15/04
Thanks Fred Fredrickson   | 08/16/04
Still makes no sense ITGuy04   | 08/16/04
Re: Thanks dhk   | 08/16/04
Re: Still makes no sense dhk   | 08/16/04
Thanks... again Fred Fredrickson   | 08/16/04
I agree...this paper was not for the lay reader dhk   | 08/16/04
I have to admit...lol..that was AWESOME.. DigitalKid   | 08/13/04
The paper wasn't written to be serious... el1jones   | 08/13/04
Because... toadlife   | 08/13/04
Oh, but it was... TechDiva_z   | 08/13/04
And it sounds like he's unprofessional to me... TimeBomb   | 08/14/04
It doesn't matter NonZealot   | 08/14/04
You're not a zealot???? Mack DaNife   | 08/15/04
Finally, some quality stuff on ZDNet..! Xunil_Sierutuf   | 08/13/04
So do you only accept articles that match your point of view? Linux_Developer   | 08/13/04
We see the light NonZealot   | 08/13/04
Please stop joking... TimeBomb   | 08/14/04
Dude nomorems   | 08/16/04
Ummm, monoculture, FilledOut   | 08/15/04
MSZealot nomorems   | 08/16/04
Far too slanted to be taken seriously Cerowyn   | 08/13/04
i think he's basing it towards MS papers on TCO Monkey_MCSE   | 08/13/04
TCO to implement??? voska   | 08/13/04
implement is just one of those grey words hipparchus2000   | 08/13/04
Why not seosamh_z   | 08/13/04
Longhorn nomorems   | 08/16/04
TC0 not TCO dhk   | 08/14/04
Hmmm... ITGuy04   | 08/16/04
Wow, productive FilledOut   | 08/14/04
ms needs to go back to making great OSs V Sanders   | 08/14/04
Odd way of putting it... AmusedAtItAll   | 08/14/04
Hey! toadlife   | 08/15/04
re: ms needs to go back to making great OSs TtfnJohn   | 08/14/04
SP2 INCLUDE Media player 9 balsover   | 08/15/04
Scary tripolitan   | 08/15/04
Re:ms needs to go back to making great OSs tripolitan   | 08/15/04
"go back to"?!? It'd be good if they start. hayesk   | 08/15/04
Mac point of view sdwood   | 08/22/04
Article based on opinion not fact EnterPrise_Analyst   | 08/15/04
Do Windows users have a sense of humour? hayesk   | 08/15/04
Some 'anti-microsoft' people are taking it way too seriously toadlife   | 08/15/04
If the show were on the other foot FilledOut   | 08/16/04
Lower cost of total ownership? (nt) Fred Fredrickson   | 08/15/04
Watch those Microsofties squirm whisperycat   | 08/16/04
Your job will be in INDIA Hamburger Chef   | 08/16/04
TAKE THAT NO_AX!!! itanalyst   | 08/16/04
you are anti-American join Abul Hamburger Chef   | 08/16/04
What The Title Of The Article Was Supposed To Be Was This: itanalyst   | 08/16/04
INDIA will own you and YOUR JOB Hamburger Chef   | 08/16/04
Degreed India Hamburger Chef Hamburger Chef   | 08/16/04

What do you think?

advertisement
advertisement