Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Mac OS X security myth exposed
Techworld ^ | 24 June 2004 | Matthew Broersma, Techworld

Posted on 01/16/2005 12:04:57 PM PST by Bush2000


24 June 2004
Mac OS X security myth exposed
And thousands of other products and OSes given security rundown.

By Matthew Broersma, Techworld

Windows is more secure than you think, and Mac OS X is worse than you ever imagined. That is according to statistics published for the first time this week by Danish security firm Secunia.

The stats, based on a database of security advisories for more than 3,500 products during 2003 and 2004 sheds light on the real security of enterprise applications and operating systems, according to the firm. Each product is broken down into pie charts demonstrating how many, what type and how significant security holes have been in each.

One thing the hard figures have shown is that OS X's reputation as a relatively secure operating system is unwarranted, Secunia said. This year and last year Secunia tallied 36 advisories on security issues with the software, many of them allowing attackers to remotely take over the system - comparable to figures on operating systems such as Windows XP Professional and Red Hat Enterprise Server.

"Secunia is now displaying security statistics that will open many eyes, and for some it might be very disturbing news," said Secunia chief executive Niels Henrik Rasmussen. "The myth that Mac OS X is secure, for example, has been exposed."

Its new service, easily acessible on its website, allows enterprises to gather exact information on specific products, by collating advisories from a large number of third-party security firms. A few other organisations maintain comparable lists, including the Open Source Vulnerability Database (OSVDB) and the Common Vulnerabilities and Exposures (CVE) database, which provides common names for publicly known vulnerabilities.

Secunia said the new service could help companies keep an eye on the overall security of particular software - something that is often lost in the flood of advisories and the attendant hype. "Seen over a long period of time,the statistics may indicate whether a vendor has improved the quality of their products," said Secunia CTO Thomas Kristensen. He said the data could help IT managers get an idea of what kind of vulnerabilities are being found in their products, and prioritise what they respond to.

For example, Windows security holes generally receive a lot of press because of the software's popularity, but the statistics show that Windows isn't the subject of significantly more advisories than other operating systems. Windows XP Professional saw 46 advisories in 2003-2004, with 48 percent of vulnerabilities allowing remote attacks and 46 percent enabling system access, Secunia said.

Suse Linux Enterprise Server (SLES) 8 had 48 advisories in the same period, with 58 percent of the holes exploitable remotely and 37 percent enabling system access. Red Hat's Advanced Server 3 had 50 advisories in the same period - despite the fact that counting only began in November of last year. Sixty-six percent of the vulnerabilities were remotely exploitable, with 25 granting system access.

Mac OS X doesn't stand out as particularly more secure than the competition, according to Secunia. Of the 36 advisories issued in 2003-2004, 61 percent could be exploited across the Internet and 32 percent enabled attackers to take over the system. The proportion of critical bugs was also comparable with other software: 33 percent of the OS X vulnerabilities were "highly" or "extremely" critical by Secunia's reckoning, compared with 30 percent for XP Professional and 27 percent for SLES 8 and just 12 percent for Advanced Server 3. OS X had the highest proportion of "extremely critical" bugs at 19 percent.

As for the old guard, Sun's Solaris 9 saw its share of problems, with 60 advisories in 2003-2004, 20 percent of which were "highly" or "extremely" critical, Secunia said.

Comparing product security is notoriously difficult, and has become a contentious issue recently with vendors using security as a selling point. A recent Forrester study comparing Windows and Linux vendor response times on security flaws was heavily criticised for its conclusion that Linux vendors took longer to release patches. Linux vendors attach more weight to more critical flaws, leaving unimportant bugs for later patching, something the study failed to factor in, according to Linux companies. Vendors also took issue with the study's method of ranking "critical" security bugs, which didn't agree with the vendors' own criteria.

Secunia agreed that straightforward comparisons aren't possible, partly because some products receive more scrutiny than others. Microsoft products are researched more because of their wide use, while open-source products are easier to analyse because researchers have general access to the source code, Kristensen said.

"A third factor is that Linux / Unix people are very concerned about privilege escalation vulnerabilities, while Windows people in general are not, especially because of the shatter-like attacks which have been known for six years or more," he said. "A product is not necessarily more secure because fewer vulnerabilities are discovered."


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: computersecurity; kneepads; littleprecious; lowqualitycrap; macuser; paidshill; redmondpayroll; tech; trollfromredmond
Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-80 ... 281-286 next last
To: Squantos; HAL9000
My advice is to get the superior weapon - the Mac.

My advice would be to evaluate your own personal needs -- and ignore the Mac Moonies.
41 posted on 01/16/2005 2:10:21 PM PST by Bush2000
[ Post Reply | Private Reply | To 22 | View Replies]

To: HAL9000

Crashes in my windows system: Zero.
Crashes doing the newspaper in a Mac: too many to count.


42 posted on 01/16/2005 2:10:46 PM PST by rwfromkansas ("War is an ugly thing, but...the decayed feeling...which thinks nothing worth war, is worse." -Mill)
[ Post Reply | Private Reply | To 22 | View Replies]

To: cyborg

Celeron is really "snaileron."

Don't get that. Make sure it is a real intel...


43 posted on 01/16/2005 2:12:35 PM PST by rwfromkansas ("War is an ugly thing, but...the decayed feeling...which thinks nothing worth war, is worse." -Mill)
[ Post Reply | Private Reply | To 28 | View Replies]

To: Squantos
Apple announced a $499 Mac last week that can use your existing PC monitor and keyboard. I hope they will continue to drop the price as the supply catches up to the demand.

As a longtime reader of your posts on this forum, I know that you recognize the virtues of quality and craftsmanship, so I'm sure you would appreciate those things in a computer too - especially if it's a good value.

44 posted on 01/16/2005 2:13:12 PM PST by HAL9000 (Spreading terrorist beheading propaganda videos is an Act of Treason!)
[ Post Reply | Private Reply | To 29 | View Replies]

To: supercat
Having a monoculture is dangerous...

Having the converse is far more expensive. And, after all, perfect security at infinite cost isn't the goal -- it's sufficient security.

It may well be that the only reason for the smaller number of attacks on Apples and Linux systems is that they're less popular and present a less-appealing tharget, even if there are no technical security advantages to them, the fact that they represent a smaller target is a major practical advantage.

Assuming that the target doesn't become more attractive if/when people start moving in that direction...

Indeed, my biggest complaint with the DOJ's attacks on Microsoft is that they completely ignored the national security implications of having an OS monoculture. Pricing and trade practices pale in importance compared to that.

You want the DOJ to tell us what OSes we should use?!? I hope that wasn't your intent.
45 posted on 01/16/2005 2:14:32 PM PST by Bush2000
[ Post Reply | Private Reply | To 20 | View Replies]

To: rwfromkansas
Crashes doing the newspaper in a Mac: too many to count.

"Bu-bu-bu-bu... Macs don't crash!" /sarcasm
46 posted on 01/16/2005 2:15:28 PM PST by Bush2000
[ Post Reply | Private Reply | To 42 | View Replies]

To: rwfromkansas; HAL9000
"OS X had the highest proportion of "extremely critical" bugs at 19 percent."

NOOOOOOOOOOOOOOOOOHHHHHHHHHHHH!!!!! Say it ain't so, Hal...
47 posted on 01/16/2005 2:16:40 PM PST by Bush2000
[ Post Reply | Private Reply | To 36 | View Replies]

To: Bush2000

You're right, but that doesn't make them any less stupid.


48 posted on 01/16/2005 2:18:30 PM PST by Doohickey ("This is a hard and dirty war, but when it's over, nothing will ever be too difficult again.”)
[ Post Reply | Private Reply | To 38 | View Replies]

To: rwfromkansas

Learned that the hard way! lol


49 posted on 01/16/2005 2:19:02 PM PST by cyborg (http://mentalmumblings.blogspot.com/)
[ Post Reply | Private Reply | To 43 | View Replies]

To: Bush2000

That is from several years ago. We use PC's now.....and only a brief period with some crashes on the PC's.

They have lots of probs in the town newspaper with their Macs though, according to the publisher.


50 posted on 01/16/2005 2:19:05 PM PST by rwfromkansas ("War is an ugly thing, but...the decayed feeling...which thinks nothing worth war, is worse." -Mill)
[ Post Reply | Private Reply | To 46 | View Replies]

To: rwfromkansas
They have lots of probs in the town newspaper with their Macs though, according to the publisher.

Most of the statewide and major city newspapers here are produced on Macs.

I haven't heard any complaints from the shops using Mac OS X, but some of the smaller papers that haven't upgraded from Mac OS 9 have occasional problems.

The Windows-based papers have the usual security and reliability problems associated with that platform.

51 posted on 01/16/2005 2:30:30 PM PST by HAL9000 (Spreading terrorist beheading propaganda videos is an Act of Treason!)
[ Post Reply | Private Reply | To 50 | View Replies]

To: Bush2000
Say it ain't so, Hal...

Number of active Mac OS X computers affected: Zero out of 14 million+.

52 posted on 01/16/2005 2:37:17 PM PST by HAL9000 (Spreading terrorist beheading propaganda videos is an Act of Treason!)
[ Post Reply | Private Reply | To 47 | View Replies]

To: HAL9000

So yer the one that reads my posts ?:o)

I'll give the MAC a peek at the store......But honestly just am not in the market for anything new in the puter worlds as I'm the wizard of progress. Same day I buy anything the manufacturers come out with something better, best and just down right awesome.

I'm gonna wait em out !


53 posted on 01/16/2005 2:40:30 PM PST by Squantos (Be polite. Be professional. But, have a plan to kill everyone you meet. ©)
[ Post Reply | Private Reply | To 44 | View Replies]

To: HAL9000

Is that a reflection of the implementation and software run on the platform, or the platform itself?


54 posted on 01/16/2005 2:41:59 PM PST by Doohickey ("This is a hard and dirty war, but when it's over, nothing will ever be too difficult again.”)
[ Post Reply | Private Reply | To 51 | View Replies]

To: HAL9000
Number of active Mac OS X computers affected: Zero out of 14 million+.

Hal, you and I both know that you can't make such assertions. You simply have no idea how many Macs have been exploited.
55 posted on 01/16/2005 2:50:50 PM PST by Bush2000
[ Post Reply | Private Reply | To 52 | View Replies]

To: Doohickey
Is that a reflection of the implementation and software run on the platform, or the platform itself?

In my opinion, the biggest factors are the operating system, the application software and user experience.

56 posted on 01/16/2005 2:50:51 PM PST by HAL9000 (Spreading terrorist beheading propaganda videos is an Act of Treason!)
[ Post Reply | Private Reply | To 54 | View Replies]

To: HAL9000
Most of the statewide and major city newspapers here are produced on Macs. I haven't heard any complaints from the shops using Mac OS X...

They're too busy recovering from crashes ...
57 posted on 01/16/2005 2:51:32 PM PST by Bush2000
[ Post Reply | Private Reply | To 51 | View Replies]

To: HAL9000

I'd re-order the factors, but that just means your experiences are different from mine.


58 posted on 01/16/2005 2:57:17 PM PST by Doohickey ("This is a hard and dirty war, but when it's over, nothing will ever be too difficult again.”)
[ Post Reply | Private Reply | To 56 | View Replies]

To: Bush2000; HAL9000

Did you two date the same woman or something?


59 posted on 01/16/2005 2:57:52 PM PST by Doohickey ("This is a hard and dirty war, but when it's over, nothing will ever be too difficult again.”)
[ Post Reply | Private Reply | To 57 | View Replies]

To: Bush2000
Hal, you and I both know that you can't make such assertions.

Sure, I can. I just did.

But don't take my word for it - here's the review of the latest iMac from The Wall Street Journal:

I am writing these words on the most elegant desktop computer I've ever used, a computer that is not only uncommonly beautiful but fast and powerful, virus-free and surprisingly affordable.

[snip]

The iMac has some less tangible advantages, too. It has a better, more modern operating system than Windows XP. It comes with a free suite of photo, video and music programs that can't be matched on Windows. And it frees users from the worry and expense of battling viruses and spyware, because there has never been a successful virus targeting the Mac operating system, and there is little or no spyware for the Mac. The many thousands of viruses and spyware programs that afflict Windows can't run on, or harm, Macs.


60 posted on 01/16/2005 3:03:51 PM PST by HAL9000 (Spreading terrorist beheading propaganda videos is an Act of Treason!)
[ Post Reply | Private Reply | To 55 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-80 ... 281-286 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson