On TechRepublic: 3 habits of highly ineffective employees
BNET Business Network:
BNET
TechRepublic
ZDNet

By Tom Espiner, News.com
Posted on ZDNet News: Jan 6, 2006 7:11:00 PM

Critics have taken aim at a study published by the U.S. Computer Emergency Readiness Team that said more vulnerabilities were found in Linux/Unix than in Windows last year.

The report, Cyber Security Bulletin 2005, was released last week. It claimed that out of 5,198 reported flaws, 812 were found in Microsoft's Windows operating system, 2,328 were found in open-source Unix/Linux systems. The rest were declared to be multiple operating-system vulnerabilities.

The report has attracted criticism from some in the open-source community. Linux vendor Red Hat said the vulnerabilities had been wrongly tagged, and so could not be used to compare the relative security of Windows and Linux/Unix platforms.

Roundup
Windows flaw gets early fix
Microsoft issues patch early after catching flak over wait.

"The study is confusing and misleading. When you look at the list, the vulnerabilities are miscategorized," Mark Cox, a consulting software engineer at Red Hat, said. "For example, Firefox is categorized as a Unix/Linux operating-system flaw, but it runs just as well on a Windows platform. Apache and PHP also run just as well on both platforms. There are methodological flaws in the statistics."

In addition, Steven Christey, an editor for Common Vulnerabilities and Exposures, an organization that maintains a common vulnerability database, said that the statistics were no basis for comparison of the relative security of Windows and Linux/Unix, because they had been collected from different sources with different criteria for the collection of flaws.

"In my opinion, refined vulnerability information sources (CVE, Bugtraq, etc.) are still a year or two away from being able to produce comparable statistics," Christey wrote in an open letter posted online.

Secunia's Thomas Kristensen agreed with Christey that the various vulnerability collection sources made comparison more difficult. "I think Steve has got some good points on why comparing vulnerability numbers is difficult," said Kristensen, chief technical officer at the security company.

CERT itself pointed out that the information in its bulletin "should not be considered the result of US-CERT analysis," as it included information from outside sources.

Taking flaw types into account
Secunia thought that the nature of the reported vulnerabilities also made it difficult to compare security on the platforms, as Linux/Unix researchers concentrate on vulnerabilities in local privilege separation, while Windows researchers look at possible remote vulnerabilities.

"Generally, many of the vulnerabilities in Linux/Unix based products are classified as local vulnerabilities, including privilege escalation, local denial of service and local exposure of sensitive data. These kind of vulnerabilities are not regarded as particularly critical, but Linux/Unix researchers tend to focus quite a lot on this category, probably because of Unix's long history of proper privilege separation. This has only recently become more relevant in Windows (NT, 2000, and XP), but many Windows researchers still focus more on remote issues," Secunia said.

The US-CERT study has also caused online debate within the open-source community. In Newsforge, the Linux and open-source online publication, Joe Brockmeier and Joe Barr cast doubt on the vulnerability totals.

"The two figures are not representative of today's two major operating-system platforms. One figure represents the vulnerabilities found in Windows operating systems: XP, NT, 98, and so on. The other represents a total figure not just for Solaris, AIX, HP-UX, the BSDs, and Linux, but for a hundred different versions of Linux," the article said.

Red Hat's Cox said Linux operating systems were more secure for businesses than Windows platforms, as fewer vulnerabilities were critical and patches were brought out more quickly.

"There is also the issue of timing," he said. "With Linux products, critical updates are available within a day. If you look at Red Hat Enterprise Linux 3, the average patch time is under a day. With the recent critical WMF (Windows Meta File) vulnerability, it took Microsoft seven days," he said

Microsoft was not available for comment at the time of writing.

Tom Espiner of ZDNet UK reported from London.

  • Talkback
  • Most Recent of 282 Talkback(s)
apparently statistics alone are meaningless
Interesting how you did not show any type of fact to backup your claim.

I would like to see any *nix exploit become news let alone become a reason to have a 0-day CERT early warning system to a... (Read the rest)
Posted by: Sgt. Pinback Posted on: 01/23/06 You are currently: Logged In | Log out
More of that famous Microsoft 'marketing'... nomorems   | 01/06/06
Mor marketing , you are right purwin@...   | 01/06/06
Mor marketing , you are right purwin@...   | 01/06/06
Man!!! To Dramatic... Cayble   | 01/06/06
Actually it's MSFT PR Chad_z   | 01/08/06
What did you expect RedHat to say... John Zern   | 01/08/06
Mikey has a brother Mark at Redhat? zmud   | 01/06/06
Naw, Mark is Mike. Anton Philidor   | 01/06/06
Drat! You beat me to it! :) [eom] techboy_z   | 01/06/06
Less space taken on the conclusion published... Anton Philidor   | 01/06/06
No! Use your noggin! techboy_z   | 01/06/06
No! Use your noggin! Stan57   | 01/06/06
What about the unreleased ones? Gibberstein   | 01/07/06
I will if you will... horusfalcon   | 01/07/06
Credibility Anton Philidor   | 01/08/06
No! Use your noggin! Protagonistic   | 01/09/06
finally, an intelligent analysis of what those numbers don't mean Sgt. Pinback   | 01/06/06
irrelevant rcb_z   | 01/06/06
RE: irrelevant Sgt. Pinback   | 01/06/06
you changed your line rcb_z   | 01/06/06
You're right but... maldain   | 01/06/06
Agree somewhat rcb_z   | 01/06/06
Web server hacks are stupid diggyk@...   | 01/06/06
Re: web server hacks are stupid rcb_z   | 01/06/06
You're right but... maldain   | 01/06/06
Your Dead Wrong !!! IceTheNet@...   | 01/06/06
Mutually exclusive software uno@...   | 01/06/06
Like there ever was a question as to which platform is more secure... michael_t   | 01/06/06
This article is poorly written if you look at comparisons crocd   | 01/06/06
Counting Consequences Harry Bardal   | 01/06/06
Most excellent post! Linux User 147560   | 01/06/06
what choice? rcb_z   | 01/06/06
Linux is not crippled anymore IceTheNet@...   | 01/06/06
I would love to cheer but..... Hrothgar - PCLinuxOS User   | 01/08/06
Mepis is not like anything you have used before IceTheNet@...   | 01/08/06
I still can't get my wireless or DSL modem up. pkr@...   | 01/09/06
is your opinion that it is bad judgment. Protagonistic   | 01/09/06
Linux is tough for techies even rcb_z   | 01/09/06
Good points, but jimk_z   | 01/06/06
The facts don't matter! whieber   | 01/06/06
Dude, no one cares about linux... No_Ax_to_Grind   | 01/06/06
NASDAQ are zealots? Yagotta B. Kidding   | 01/06/06
RE: NASDAQ are zealots? Linux User 147560   | 01/06/06
And major corporations davidr69   | 01/06/06
And Spikey_Mike   | 01/06/06
Dude, no one cares about... JusPassinThrough   | 01/06/06
Dude, Your ignorace is showing IceTheNet@...   | 01/08/06
ignorace = Ignorance IceTheNet@...   | 01/08/06
Actually I Do Hrothgar - PCLinuxOS User   | 01/09/06
Amazing linux has so many issues when no one use it. No_Ax_to_Grind   | 01/06/06
Which Linux are you talking about.... Anti_Zealot   | 01/06/06
Just fishin Linux User 147560   | 01/06/06
Don't take it personal IceTheNet@...   | 01/08/06
as usual DemonX   | 01/06/06
Perhaps for the desktop market balsover   | 01/06/06
That's user mentality voska   | 01/09/06
Experts question Windows win in flaw tally Loverock Davidson   | 01/06/06
RE: Experts question Windows win in flaw tally richdave   | 01/06/06
It depends Loverock Davidson   | 01/06/06
It depends richdave   | 01/06/06
No Loverock Davidson   | 01/06/06
RE: No richdave   | 01/06/06
Don't do that Anti_Zealot   | 01/06/06
RE: No Protagonistic   | 01/06/06
LOL Loverock Davidson   | 01/06/06
Actually loverock tracy anne   | 01/06/06
was done in a true FUD fashion Sgt. Pinback   | 01/07/06
'...linux is quickly being phased out...' TheBoyBailey   | 01/06/06
Its true Loverock Davidson   | 01/06/06
And your proof is where? balsover   | 01/06/06
You assume too much . . . Boy jthomas007   | 01/07/06
linux is quickly being phased out. pkr@...   | 01/09/06
You can't just count the flaws. You also have to... BitTwiddler   | 01/06/06
You can obviously see which side you're on. geewhizbang   | 01/06/06
Since the M$ patch is so easy to install jobranovich@...   | 01/06/06
Such a witty reply. Not. geewhizbang   | 01/07/06
It's Actually Easier With Linux Edward Meyers   | 01/07/06
Yes, I have tried Linux, but not recently geewhizbang   | 01/07/06
Corel Linux- You're Joking Edward Meyers   | 01/07/06
Corel Linux geewhizbang   | 01/08/06
I was not exaggerating about the exploits geewhizbang   | 01/07/06
Is that really easier than Selecting OK? Hrothgar - PCLinuxOS User   | 01/09/06
OK isn't cool Fujikid   | 01/10/06
Shows how little you know ebrke   | 01/09/06
The patch requires a reboot voska   | 01/09/06
Such a witty reply. Not. geewhizbang   | 01/07/06
auto-update on linux is not only simpler, it is more flexible Sgt. Pinback   | 01/08/06
ARRRGGH!!!!! Hrothgar - PCLinuxOS User   | 01/09/06
Ok :-) HeeHee Fujikid   | 01/10/06
plug-and-pray is part of the problem, not the solution Sgt. Pinback   | 01/08/06
Rep and I are celebrating... Mike Cox   | 01/06/06
i love it MIS Master   | 01/06/06
RE: i love it richdave   | 01/06/06
Mike is my hero... SGT_Spam   | 01/06/06
Mike is my hero... richdave   | 01/06/06
Space Heater SGT_Spam   | 01/06/06
RE: Space Heater richdave   | 01/06/06
Virus Cleaning justmeinok@...   | 01/06/06
Rep and I are celebrating... Protagonistic   | 01/06/06
brownies IceTheNet@...   | 01/06/06
brownies Protagonistic   | 01/06/06
Is Mark Cox your "good" twin? olePigeon   | 01/09/06
Not looking everywhere? rcb_z   | 01/06/06
Misinterpretation Yagotta B. Kidding   | 01/06/06
how else to interpret? rcb_z   | 01/06/06
How to interpret Update victim   | 01/06/06
Guessing rcb_z   | 01/06/06
No, that's not a guess... techboy_z   | 01/06/06
More guessing rcb_z   | 01/06/06
Consider that Unix based systems have Linux User 147560   | 01/06/06
not to mention social hacking IceTheNet@...   | 01/06/06
Still a theory rcb_z   | 01/06/06
Says who? Fred Fredrickson   | 01/07/06
who is looking? rcb_z   | 01/08/06
Linux advocates need to make up their minds... ye   | 01/06/06
not core components Sgt. Pinback   | 01/06/06
RE: Linux advocates need to make up their minds... richdave   | 01/06/06
I can't speak for you but... NonZealot   | 01/06/06
RE: I can't speak for you but... richdave   | 01/06/06
I agree for the technically knowledgeable NonZealot   | 01/06/06
RE: I agree for the technically knowledgeable richdave   | 01/06/06
Ahh, so the solution doesn't have to be useable NonZealot   | 01/06/06
RE: Ahh, so the solution doesn't have to be useable richdave   | 01/06/06
Don't forget... Linux User 147560   | 01/06/06
You're back Richard Flude   | 01/06/06
RE: You're back richdave   | 01/06/06
KDE TimeBomb   | 01/06/06
You should be embarrassed diggyk@...   | 01/06/06
You should be embarrassed, nya nya! NonZealot   | 01/06/06
Really? diggyk@...   | 01/06/06
No it's not Linux User 147560   | 01/06/06
MSIE is used for things other than.... dsentman@...   | 01/06/06
I will do my best to explain IceTheNet@...   | 01/07/06
I could kill the explorer process zmud   | 01/07/06
RE: Now who should be "embarassed"? Protagonistic   | 01/06/06
Agreed on a couple points NonZealot   | 01/06/06
Doesn't that make Windows useless to? diggyk@...   | 01/06/06
The NT Kernel is useless by itself NonZealot   | 01/06/06
Not Linux zealots diggyk@...   | 01/06/06
and augmented with html, IE, http, smtp related dlls is even michael_t   | 01/06/06
RE: Agreed on a couple points richdave   | 01/06/06
Not trying to be unfair Richard Flude   | 01/06/06
Re: Linux advocates need to make up their minds... none none   | 01/06/06
Beleive this, real IT people take the study seriously. No_Ax_to_Grind   | 01/06/06
Sorry Axey, You're Not A "Real" IT Person itanalyst   | 01/06/06
Either way, he's still correct John Zern   | 01/06/06
Oh, we ALWAYS take these things seriously... Judas I.   | 01/06/06
Bedroom admins? diggyk@...   | 01/06/06
the value of wallpaper? cburgess-iPALADIN   | 01/11/06
Until they read it SGT_Spam   | 01/06/06
SOME IT shops take it as gospel davidr69   | 01/06/06
Nicely said diggyk@...   | 01/06/06
Nicely said diggyk@...   | 01/06/06
Serious IT people laugh at this transparent "studies" but michael_t   | 01/06/06
Just one question JusPassinThrough   | 01/06/06
What do you mean by real IT people? quantumstate   | 01/07/06
Real IT B280Programmer   | 01/07/06
Walmart's "Real IT" was hacked... cburgess-iPALADIN   | 01/11/06
What "study" are you referring to? Sgt. Pinback   | 01/07/06
M$ shills are spreading FUD! Linux Geek   | 01/06/06
knew it wouldn't take long Shelendrea   | 01/06/06
Difference Between Windows Vulnerability And Linux Vulnerability itanalyst   | 01/06/06
Mythology rcb_z   | 01/06/06
Nice theory! JusPassinThrough   | 01/07/06
Linux not good enough for malware rcb_z   | 01/07/06
Hmmm.... bchesmer   | 01/07/06
Denial won’t make it go away prong@...   | 01/08/06
Not quite so simple quantumstate   | 01/07/06
Distinction rcb_z   | 01/07/06
You would think they would take the feedback to improve it. osreinstall   | 01/06/06
Agree 100% (nt) NonZealot   | 01/06/06
If you two agree then so do I! Loverock Davidson   | 01/06/06
thanks God... I had some doubts but now I am certain michael_t   | 01/06/06
We knew that! bchesmer   | 01/07/06
Here's the E-mail address SGT_Spam   | 01/06/06
Ahh, the old "not my problem" answer! NonZealot   | 01/06/06
More like closed mindness SGT_Spam   | 01/06/06
reply pandora83   | 01/09/06
Interesting diggyk@...   | 01/06/06
Not my problem uno@...   | 01/06/06
Did I hit a nerve? osreinstall   | 01/06/06
No, You Are Just Making Noise Edward Meyers   | 01/06/06
Well Edward... Linux User 147560   | 01/06/06