Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


June 24, 2007

Microsoft: Vista More Secure than OS X, Linux

RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Microsoft: Windows Vista More Secure than OS X, Linux

by Paul Thurrott, thurrott@windowsitpro.com

Following up on his previous Vista vulnerability report that was released 90 days after the initial public release of Vista, Microsoft Strategy Director Jeff Jones recently published a Vista 6-month vulnerability report. This report examined the state of Vista security in the first six months of the system's availability and answers one criticism about the first report: that it covered too short a timeframe to be relevant. But Jones' new report is controversial for other reasons. You see, the data he provided demonstrates that Vista is, in fact, more secure than competitors such as OS X and Linux.

Big mistake.

For those not familiar with today's tech landscape, OS X and Linux users are among the most stridently vocal about their favorite OSs, and they don't take this criticism at face value: To them, almost any OS is more secure than Windows. To suggest otherwise is hearsay, evidence be damned.

To be fair, both OS X and Linux are successfully hacked far less frequently than Windows. One of the reasons, of course, is that Windows is simply installed on more PCs and is a much more obvious choice for hackers to attack. But the data that Jones presents suggests that Vista, in particular, is subjected to fewer dangerous security bugs than the competition, which is a related (but not identical) conversation. In other words, OS X and Linux might have more severe security flaws. But Windows, obviously, is attacked more frequently in the real world. So which system is really "more secure"?

"Windows Vista continues to show a trend of fewer total and fewer high severity vulnerabilities at the six month mark compared to its predecessor product Windows XP and compared to other modern competitive workstation OSes," Jones writes. "This affirms the early results that we found after 90 days and provides a supporting indicator that the Microsoft Security Development Lifecycle (SDL) process and heightened focus on security is having a positive impact on Microsoft Windows in terms of fewer vulnerabilities."

Jones's report shows that Microsoft released four updates to fix 12 Vista security flaws in the OS's first six months on the market; none were rated high severity. Additionally, four other Vista security flaws were identified in this time period but haven't yet been fixed, with one flaw rated high severity. Jones then compared this information to similar data for Windows XP, Red Hat Enterprise Linux 4 Workstation (using a reduced component set installation), Ubuntu Linux 6.06 LTS reduced component set, Novell SUSE Linux Enterprise 10 reduced component set, and Mac OS X 10.4.

Although XP compared favorably to Vista, the other OSs did not: The Linux-based OSs and Mac OS X suffered from more fixed vulnerabilities, more unfixed vulnerabilities, and more high severity vulnerabilities in their first six months of release than either Windows version. And Vista proved to be the most secure OS, by these measures, overall.

Naturally, OS X and Linux partisans can point to several offsetting concerns, such as the high rate of attacks for Windows-based vulnerabilities. But Windows users can at least take solace in the fact that Microsoft's SDL appears to be having a positive effect on its products. And Jones promises a follow-up report at the one-year anniversary of Vista's release. Expect that report to also be highly controversial.

If you're interested in Jeff Jones's report, you can download the PDF from the CSO Web site.
http://www.csoonline.com/pdf/6_Month_Vista_Vuln_Report.pdf

End of Article



Reader Comments
Speaking at the intelligence level that Yawn would...eat that @tards!!!

--tayme

tayme June 24, 2007 (Article Rating: )


Oh, but wait...this is FUD that is bing spread by the retarded M$ CS...right Yawn???

tayme June 24, 2007 (Article Rating: )


The biggest issue facing Microsoft as far as security goes is perception. Microsoft software for several years was extremely insecure, and as such Microsoft earned that reputation. Over the last several years, though, Microsoft has made amazing strides in improving the security of Windows, and Vista is the fruits of that labor. Microsoft now needs to begin changing the perception.

jersey72 June 25, 2007 (Article Rating: )


And since no software is 100% secure, what also matters is how you handle security issues that do come up. And in this case, MS has made huge strides to handle those. Even with the somewhat controversial patch Tuesday, it is still much better than in the past. Getting updates from MS is such a painless process for Vista users, and is solid for XP users. And the excellent and FREE WSUS makes it very easy to patch computers across businesses of varying sizes.

I think you are right about perception, jersey. They still have a very negative aura around them, due to the glaring security and reliability problems of the past, and the convicted monopoly status. The MS haters don't realize that MS is over these two bad humps, and has become a much changed and better company.

Side note: The page that I am viewing and typing in right now has a link for top viewed articles, and it shows articles from 2002 and 2003. I would seriously doubt that is the case, but it is one of those crazy site problems that we experience on a daily basis here. Sigh.

Dipsh t Admin June 26, 2007 (Article Rating: )


"...one of those crazy site problems that we experience on a daily basis here."

Probably just some dipsh*t administrator that can't fix the problem because it doesn't have a "wizard".

;-) <-----the all-inclusive wink of forgiveness

lotsamystuff June 26, 2007 (Article Rating: )


I'm sure statistics like this will be buried in the back-pages because of the I-pone...

Good news for MS never-the-less...

sx4sport@hotmail.com June 26, 2007 (Article Rating: )


dipsh1t admin > "genius" any day!

XP

Waethorn June 26, 2007 (Article Rating: )


ROFL, this "study" has already been shredded apart. Not counting IE vulnerabilities, for instance, while counting Safari vulnerabilities is highly disingenuous but typical of Microsoft. Things like this are only put out to try to encourage the already low morale of the fanboys, like yourselves.

It's gotta be tough given how massively huge a flop Vista has been in both security and sales figures. Microsoft is dying.

Preseton June 29, 2007 (Article Rating: )


"dipsh1t admin > "genius" any day!"

Preseton just proves my point.

XP

Waethorn June 30, 2007 (Article Rating: )


You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

WinInfo Short Takes: Week of November 9, 2009

An often irreverent look at some of the week's other news, including some more Windows 7 sales momentum, some Sophos stupidity, Microsoft's cloud computing self-loathing, more whining from the browser makers, Zoho's "Fake Office," and much, much more ...

Understanding File-Size Limits on NTFS and FAT

A general confusion about files sizes on FAT seems to stem from FAT32's file-size limit of 4GB and partition-size limit of 2TB. ...


Security Whitepapers Reducing the Costs and Risks of Branch Office Data Protection

Solving Desktop Management Challenges in Healthcare

Solving Desktop Management Challenges in Education

Related Events WinConnections and Microsoft® Exchange Connections

Deep Dive into Windows Server 2008 R2 presented by John Savill

Introduction to Identity Lifecycle Manager "2"

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement