Wednesday, February 01, 2006
Windows Vulnerabilities vs Linux Vulnerabilities
CERT recently reported on the number of Linux/Unix and Windows vulnerabilities discovered in 2005. There were nearly 4 times as many Linux/Unix vulnerabilities found in '05 as there were Windows vulnerabilities. (Linux/Unix 2,328 vs Windows 812).
A colleague and I were discussing the numbers and his spin on it was that this trend will continue with the number of Windows vulnerabilities declining over time and the Linux/Unix vulnerabilities stabilising or slightly increasing. His reasoning (and I totally agree) is that Microsoft has got very serious about secure code and security by default whereas the Linux/Unix side of the fence is more fragmented and often contributed to via Open Source by well meaning but possibly not security minded folk.
A colleague and I were discussing the numbers and his spin on it was that this trend will continue with the number of Windows vulnerabilities declining over time and the Linux/Unix vulnerabilities stabilising or slightly increasing. His reasoning (and I totally agree) is that Microsoft has got very serious about secure code and security by default whereas the Linux/Unix side of the fence is more fragmented and often contributed to via Open Source by well meaning but possibly not security minded folk.