Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

June 24, 2007 12:00 AM

Microsoft: Vista More Secure than OS X, Linux

Windows IT Pro
InstantDoc ID #96387
Rating: (9)

Microsoft: Windows Vista More Secure than OS X, Linux

by Paul Thurrott, thurrott@windowsitpro.com

Following up on his previous Vista vulnerability report that was released 90 days after the initial public release of Vista, Microsoft Strategy Director Jeff Jones recently published a Vista 6-month vulnerability report. This report examined the state of Vista security in the first six months of the system's availability and answers one criticism about the first report: that it covered too short a timeframe to be relevant. But Jones' new report is controversial for other reasons. You see, the data he provided demonstrates that Vista is, in fact, more secure than competitors such as OS X and Linux.

Big mistake.

For those not familiar with today's tech landscape, OS X and Linux users are among the most stridently vocal about their favorite OSs, and they don't take this criticism at face value: To them, almost any OS is more secure than Windows. To suggest otherwise is hearsay, evidence be damned.

To be fair, both OS X and Linux are successfully hacked far less frequently than Windows. One of the reasons, of course, is that Windows is simply installed on more PCs and is a much more obvious choice for hackers to attack. But the data that Jones presents suggests that Vista, in particular, is subjected to fewer dangerous security bugs than the competition, which is a related (but not identical) conversation. In other words, OS X and Linux might have more severe security flaws. But Windows, obviously, is attacked more frequently in the real world. So which system is really "more secure"?

"Windows Vista continues to show a trend of fewer total and fewer high severity vulnerabilities at the six month mark compared to its predecessor product Windows XP and compared to other modern competitive workstation OSes," Jones writes. "This affirms the early results that we found after 90 days and provides a supporting indicator that the Microsoft Security Development Lifecycle (SDL) process and heightened focus on security is having a positive impact on Microsoft Windows in terms of fewer vulnerabilities."

Jones's report shows that Microsoft released four updates to fix 12 Vista security flaws in the OS's first six months on the market; none were rated high severity. Additionally, four other Vista security flaws were identified in this time period but haven't yet been fixed, with one flaw rated high severity. Jones then compared this information to similar data for Windows XP, Red Hat Enterprise Linux 4 Workstation (using a reduced component set installation), Ubuntu Linux 6.06 LTS reduced component set, Novell SUSE Linux Enterprise 10 reduced component set, and Mac OS X 10.4.

Although XP compared favorably to Vista, the other OSs did not: The Linux-based OSs and Mac OS X suffered from more fixed vulnerabilities, more unfixed vulnerabilities, and more high severity vulnerabilities in their first six months of release than either Windows version. And Vista proved to be the most secure OS, by these measures, overall.

Naturally, OS X and Linux partisans can point to several offsetting concerns, such as the high rate of attacks for Windows-based vulnerabilities. But Windows users can at least take solace in the fact that Microsoft's SDL appears to be having a positive effect on its products. And Jones promises a follow-up report at the one-year anniversary of Vista's release. Expect that report to also be highly controversial.

If you're interested in Jeff Jones's report, you can download the PDF from the CSO Web site.
http://www.csoonline.com/pdf/6_Month_Vista_Vuln_Report.pdf

Related Content:

ARTICLE TOOLS

Comments
  • Joe
    5 years ago
    Jun 30, 2007

    "dipsh1t admin > "genius" any day!"

    Preseton just proves my point.

    XP

  • Preston
    5 years ago
    Jun 29, 2007

    ROFL, this "study" has already been shredded apart. Not counting IE vulnerabilities, for instance, while counting Safari vulnerabilities is highly disingenuous but typical of Microsoft. Things like this are only put out to try to encourage the already low morale of the fanboys, like yourselves.

    It's gotta be tough given how massively huge a flop Vista has been in both security and sales figures. Microsoft is dying.

  • Joe
    5 years ago
    Jun 26, 2007

    dipsh1t admin > "genius" any day!

    XP

  • sx4sport@hotmail.com
    5 years ago
    Jun 26, 2007

    I'm sure statistics like this will be buried in the back-pages because of the I-pone...

    Good news for MS never-the-less...

  • Lotsa
    5 years ago
    Jun 26, 2007

    "...one of those crazy site problems that we experience on a daily basis here."

    Probably just some dipsh*t administrator that can't fix the problem because it doesn't have a "wizard".

    ;-) <-----the all-inclusive wink of forgiveness

You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.