Subscribe to Windows IT Pro
August 09, 2011 09:13 AM

Security Expert: Windows 7 Is More Secure Than Mac OS X

Windows IT Pro
InstantDoc ID #140118
Rating: (86)

Conventional wisdom has it that Apple's Mac OS X system is more secure than Windows. And though partisans on either side of the OS fence have differing reasons for believing that to be so—Mac users believe it's because of the inherent superiority of OS X's UNIX underpinnings, and Windows users claim that OS X's tiny 5 percent usage share isn't a sufficient target for hackers—this is perhaps the one area where they do agree.

But security expert Alex Stamos of iSec Partners says the conventional wisdom is wrong. And this week at the Black Hat Conference, he claimed that Mac OS X is "significantly more vulnerable" than Windows 7 when it comes to network-based attacks—you know, the kind that actually occur in the real world.

Catch your breath a moment so the dust can settle: As you read this, a thousand tiny-minded technology enthusiasts are busy exercising their bile gene in profanity-laced email messages, on Twitter, and in anonymous comment-section posts. They'll calm down. Just give it some time.

And in the interest of full disclosure, various versions of Mac OS X did suffer from fewer overall vulnerabilities over the past three years than did various versions of Windows: There were 1,151 major OS X vulnerabilities in this time period, compared with 1,325 for Windows. (But even those figures should temper any talk of OS X's "inherent" superiority. Just a thought.)

But when you look at the most recent versions of OS X and Windows, and examine network-based attacks specifically, the tables are turned: Modern Windows versions are more secure overall than the latest OS X versions, and with network-based vulnerabilities in particular, OS X comes out way behind.

"OS X networks are significantly more vulnerable to network privilege escalation," Stamos said at the show. "Almost every OS X server service offers weak or broken authentication mechanisms."

Stamos also threw cold water on the notion that OS X is too small of a target for hackers to bother with, and he notes the small difference between overall OS X and Windows vulnerabilities over the past three years as proof. If hackers were ignoring OS X as predicted, those vulnerabilities would never have been found.

He also points out that a false sense of security leads Mac users to think they are invulnerable to hacking, and Apple's "deceptive" advertising doesn't help. Mac users are more prone to social-engineering attacks than Windows users simply because they don't have the security religion.

Of course, Apple has just shipped its latest OS X release, Lion, and that version of OS X will eventually require new applications to enforce a security sandboxing model that should help very new applications from spreading malicious code. And on the iOS side—Apple's iPhone and iPad are based on an OS X-like OS themselves—the company has always provided a more secure sandboxing model, which raises hopes that these devices will be more secure going forward, too.

(Modern OS X and Windows systems include many similar or security features, by the way, including such things as ASLR, which randomizes the memory location of startup applications, and NX/DEP/ED, another set of memory-based protections.)

What Microsoft has going in its favor, of course, is a fanatical devotion to security: After shutting down OS development in 2002 to address rampant security vulnerabilities in Windows XP, the company initiated its Trustworthy Computing program and now develops all products under an ever-improving Security Development Lifecycle (SDL) process that none of its competitors have come even close to adopting. The SDL has been so successful, in fact, that hackers have turned from OSs to popular applications in recent years because Windows has become so secure. Just ask Adobe how that change has affected its business.

The point is that things change. In my experience, it's not at all hard to properly secure a Windows PC, and common sense goes a long way when it comes to online activities. I'm not sure I'd personally promote the notion that Windows is "more secure" than OS X, but I am arguing that they're within shouting distance of each other and are certainly comparable from a security standpoint. Of course, for Mac users, that's probably an affront to every notion they hold dear. Hopefully, their comeuppance won't be as painful as the one PC users faced almost a decade ago.

Related Content:

ARTICLE TOOLS

Comments
  • bagbig
    9 months ago
    Aug 16, 2011

    Hello, everybody, the good shoping place, the new season approaching, click in.
    Welcome to ==== http://www.voguecatch.com ==
    Air Jordan (1-24) shoes $35
    UGG BOOT $50
    Nike shox (R4, NZ, OZ, TL1, TL2, TL3) $35
    Handbags ( Coach Lv fendi D&G) $35
    T-shirts (polo, ed hardy, lacoste) $16
    Jean (True Religion, ed hardy, coogi)$34
    Sunglasses ( Oakey, coach, Gucci, Armaini)$15
    New era cap $16
    Bikini (Ed hardy, polo) $18 http://www.voguecatch.com
    FREE SHIPPING
    === http://www.voguecatch.com

    === http://www.voguecatch.com

    === http://www.voguecatch.com

    === http://www.voguecatch.com

    === http://www.voguecatch.com

    === http://www.voguecatch.com

    === http://www.voguecatch.com

    === http://www.voguecatch.com ===

    ===http://www.voguecatch.com===

  • Rsun
    9 months ago
    Aug 11, 2011

    Whenver I read Paul's statements about the superior security of Windows, I think about the monthly email I get from Microsoft, detailing the security bulletins for the month. Interesting that Paul would post this news item on the same day that MS releases 13 security bulletins.
    http://www.microsoft.com/technet/security/bulletin/ms11-aug.mspx

  • --tayme
    9 months ago
    Aug 11, 2011

    @chuck - You are right...but on the opposite side we have people like dcortex spreading false rumors or half truths. So, Paul evens it out I guess.

  • chuckb84
    9 months ago
    Aug 10, 2011

    For the nth time: There is a big difference between "theoretical vulnerabilities" and real security problems. We have this silly thing that we use---scientists call it "data"--that let us empirically determine which OS is secure and which isn't.

    OS X has no, none, zip, zero, nada, zilch, bupkis, real security issues that involve propagating viruses in the real world. It's just a fact. These are, as Paul says "you know, the kind that actually occur in the real world."

    Or, more to the point, that have NEVER, not ONCE, occurred on any version of OS X.

    But, Henny Penny could be right some day, and this type of issue MAY occur some day for OS X. To date, is has not, and that's a 10 year track record. Even a casual purusal of the history of Windows security issues in the past decade will put to rest any question about which OS is more secure.

    When OS X is inevitably hacked, I'm sure Paul will trumpet it like the second coming. It won't change anything though, about the relative security of Windows and OSX; we already have a decade of data on that.

  • infiniteloop
    9 months ago
    Aug 10, 2011

    @dolphinlover:

    If Kindel stopped using his Windows Phone, imagine how much Market share Windows Phone would lose.

You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.