Language Selection

English French German Italian Portuguese Spanish

Red Hat and Firefox more buggy than Microsoft?

Filed under
Security

Secunia has found that the number of security bugs in the open source Red Hat Linux operating system and Firefox browsers far outstripped comparable products from Microsoft last year.

Out of the operating systems monitored by Secunia - Windows (98 and onwards), Mac OS X, HP-UX 10.x and 11.x, Solaris 8, 9, and 10 and Red Hat (excluding Fedora) - Red Hat was found to have by far the most vulnerabilities, at 633, with 99 percent found in third-party components. (Linux distributions are generally composed mostly of third-party software, which is integrated by the distributor.)

Red Hat has taken issue with the figures, claiming the accurate number should be 404 vulnerabilities for last year.

Windows had only 123 bugs reported, but 96 percent of those were found in the operating system itself.

More Here




Red Hat bugs - another open source PR hit?

Red Hat and Firefox are reported to have more bugs in them than their Microsoft equivalents. But the truth is, as always, more complex. And once again, security is shown as a key point where rival approaches are bidding to distinguish themselves.

Secunia reported the discrpancy, stating in its 2007 Report that Red Hat had 633 flaws, compared with Windows' 123. However, Red Hat's Mark Cox quickly pointed out in a blog that a) the number was wrong, Cool it counted flaws in all the third party products associated with Red Hat's OS, and worst of all c) it counted several bugs six times, since it added up fixes made for the same bug, on multiple Red Hat products.

The interesting thing is why Secunia would push this story at all.

More Here

Firefox is fixed faster

Counting security vulnerabilities to compare the security of different software projects is flawed. It is only a useful metric if you are comparing a project to itself over time. I’ve discussed this topic here and here. It’s even more ridiculous to try and compare an open source bug count to a closed source project because you can see all the bugs in an open source project. You can only see the publicly found security issues for a closed source product, like Internet Explorer.

So what is interesting in the Techworld article is the measures of real risk to users:

More Here

Good additions there

When I saw the headline I was going to post these rebuttal articles too, but you beat me to it. Nice review of MEPIS BTW...

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.

More in Tux Machines

5 fundamental differences between Windows 10 and Linux

This comparison really only scratches the surface. And don't get me wrong, there are areas where Windows 10 bests Linux (few, but they do exist). In the end, however, the choice is yours. Chances are you'll be making the choice based on which platform will allow you get more work done and do so with a certain level of efficiency and reliability. I would highly recommend, to anyone, if Linux can enable you to get your work done...give it a go and see if you don't find it more dependable and predictable. Read more

Firefly COM dual boots Android and Ubuntu on hexa-core RK3399

GNOME developer Bastien Nocera talks in his latest blog post about the enhancements he managed to implement in the past few weeks to the Bluetooth stack of the Fedora Linux operating system. Read more

Games: Morphite, Mooseman, Arma, and PlayStation 4 DualShock Controller

  • Stylish FPS 'Morphite' released without Linux support, but it's coming
    Sadly, Morphite [Steam] has seen a delay with the Linux version. Thankfully, the developer was quick to respond and it's still coming.
  • The Mooseman, a short side-scrolling adventure just released for Linux
    In the mood for something a little out there? Well, The Mooseman [Steam] a short side-scroller might just hit the spot.
  • Arma 3 1.76 for Linux is planned, work on it to start "soon"
    Bohemia Interactive have announced in their latest "SITREP" that the Linux version of Arma 3 will be updated to the latest version of 1.76, work is set to start on it "soon".
  • Sony's PlayStation 4 DualShock Controller Now Supported in Fedora Linux, GNOME
    GNOME developer Bastien Nocera talks in his latest blog post about the enhancements he managed to implement in the past few weeks to the Bluetooth stack of the Fedora Linux operating system. The patches submitted by the developer to the Bluetooth packages in the latest Fedora Linux release promise to bring improvements to the way PlayStation 3 DualShock controllers are set up in the environment if you're using the GNOME desktop environment. Until now, to set up a DualShock 3 controller, users had to plug it in via USB, then disconnect it, and then press the "P" button on the joypad, which would have popped-up a dialog to confirm the Bluetooth connection. But this method had some quirks though.

Debian Development Reports

  • Free software log (July and August 2017)
    August was DebConf, which included a ton of Policy work thanks to Sean Whitton's energy and encouragement. During DebConf, we incorporated work from Hideki Yamane to convert Policy to reStructuredText, which has already made it far easier to maintain. (Thanks also to David Bremner for a lot of proofreading of the result.) We also did a massive bug triage and closed a ton of older bugs on which there had been no forward progress for many years. After DebConf, as expected, we flushed out various bugs in the reStructuredText conversion and build infrastructure. I fixed a variety of build and packaging issues and started doing some more formatting cleanup, including moving some footnotes to make the resulting document more readable.
  • Freexian’s report about Debian Long Term Support, August 2017
    Like each month, here comes a report about the work of paid contributors to Debian LTS.
  • Reproducible Builds: Weekly report #125
    16 package reviews have been added, 99 have been updated and 92 have been removed in this week, adding to our knowledge about identified issues.