Language Selection

English French German Italian Portuguese Spanish

Microsoft vs Linux Reports - Sheer Waste Of Time?

Filed under
Linux
Microsoft

The report released by Security Innovation Inc., an application security company, comparing Windows Server 2003 security with Red Hat Enterprise Linux 3 Enterprise Server (RHEL3ES) is very interesting in its own right. Just skimming through the report reveals a few discrepancies that question its credibility.

The main page briefing about the paper states:
"Results of Independent Research Project that Microsoft Windows Server 2003 has Fewer Security Flaws than Multiple Configurations of a Compatible Linux Server." While the researchers are clearly mentioning the Microsoft product the use the more generic term "Linux". Why generalize? It is hard to believe that these PhDs do not understand the relevance of this statement. Why couldn't they just be direct and mentioned "RHEL3ES?"

In the report:
"Aside from beliefs over the relative "security" of the closed versus Open Source development paradigms, another important contributing factor is that Microsoft develops and releases all the components in their Web server stack. This allows Microsoft more control over release cycles and vulnerability disclosures than the distributed development method."

This brings up a couple of interesting points. Firstly, according to them implementing multiple components (software) in an enterprise makes the overall system more vulnerable. Well, so we must expect enterprises to immediately take actions to ensure that ALL their ERP, SCM, CRM, and, of course, Web Servers are from a single vendor. Though we hate to repeat this but have they ever heard of something called "vendor lock-in".

Secondly, the report states that Microsoft has control over release cycles AND VULNERABILITY DISCLOSURES. Do they intend to say that the "days of risk" has been significantly affected by the fact that the vendor has control as to when the vulnerability will be disclosed?

A little later comes:
"Another factor which helps Microsoft in terms of average days of risk is that Microsoft strongly encourages a "responsible disclosure" policy - that is, the company attempts to carefully coordinate vulnerability announcement with fix announcement and actively build relationships with new security researchers."

It does seem that the report is trying to explain that the companies buying the Microsoft products are supposed to work closely with Microsoft to ensure that the vulnerability announcement and fix announcements are as close as possible to ensure that the "days of risk" are kept to a minimum. We sincerely hope that we got this one wrong.

Though a lot more can be analyzed in the report, it does appear that "independent" research seems to have been done (or should we say, written) by people who think that Enterprise IT Heads are a bunch of fools who have all the time on earth to read through tones of pages of deceptive analysis.

Source.

More in Tux Machines

Containers: Resin.IO and Platform9

  • Resin.IO puts Linux and containers to work for IoT
    Resin.IO is working to make the use of containers and microservices useful tools to developers of Linux-based Internet of Things (IoT) applications. CEO Alexandros Marinos said the company has been working for three years to make mainstream containers attractive to developers of embedded workloads, such as those found in IoT applications. The company calls this the "Industrial Internet."
  • Platform9 Unveils Open Source Serverless Computing Framework
    Serverless computing is rapidly emerging as one of the favorite ways developers programmatically invoke cloud infrastructure. Instead of having to be aware of how their applications are consuming IT infrastructure, a serverless computing framework employs an event-driven architecture to make additional infrastructure resources available in real time as an application scales up and down. Today, Platform9 launched Fission, an open source implementation of a serverless computing framework based on the Kubernetes container orchestration engine originally developed by Google.

Wine 2.0

  • Wine Announcement
    The Wine team is proud to announce that the stable release Wine 2.0 is now available.
  • Wine 2.0 is now officially available
    I just got the announce email from the Wine team that Wine 2.0 is now officially available. It's an absolutely massive release! For those sticking with development builds, you obviously won't really see a difference, but for those sticking to stable releases it's huge.
  • Wine 2.0 Makes Its Debut
    Wine 2.0 is now officially available. Wine 2.0 is the first release from WineHQ under their new time-based (annual) release cadence, following the Wine 1.9 development series. Wine 2.0 has many new features including GStreamer 1.0 support, Direct3D 9/11 improvements, X11 improvements, Direct2D enhancements, better support for many different Windows games, support for Microsoft Office 2013, and thousands of other changes in total.
  • Wine 2.0 Released, Supports Microsoft Office 2013
    A brand new stable release of Wine, the Windows compatibility programme, is now available to download. Wine 2.0 — yes, 2.0 — follows more than a year of development effort and marks the start of a new timed-based release cadence.

BlankOn Linux explained

Hi guys, welcome to the 15th segment of "Introduction with Linux Distro". We have made quite a few introductions from the start of this website, every segment has something unique to itself. So this time we will be having a Linux distribution which have pure philosophy and creativity, as our guest. Let's get to know more about BlankOn Linux. Read more

today's leftovers