Language Selection

English French German Italian Portuguese Spanish

Microsoft vs Linux Reports - Sheer Waste Of Time?

Filed under
Linux
Microsoft

The report released by Security Innovation Inc., an application security company, comparing Windows Server 2003 security with Red Hat Enterprise Linux 3 Enterprise Server (RHEL3ES) is very interesting in its own right. Just skimming through the report reveals a few discrepancies that question its credibility.

The main page briefing about the paper states:
"Results of Independent Research Project that Microsoft Windows Server 2003 has Fewer Security Flaws than Multiple Configurations of a Compatible Linux Server." While the researchers are clearly mentioning the Microsoft product the use the more generic term "Linux". Why generalize? It is hard to believe that these PhDs do not understand the relevance of this statement. Why couldn't they just be direct and mentioned "RHEL3ES?"

In the report:
"Aside from beliefs over the relative "security" of the closed versus Open Source development paradigms, another important contributing factor is that Microsoft develops and releases all the components in their Web server stack. This allows Microsoft more control over release cycles and vulnerability disclosures than the distributed development method."

This brings up a couple of interesting points. Firstly, according to them implementing multiple components (software) in an enterprise makes the overall system more vulnerable. Well, so we must expect enterprises to immediately take actions to ensure that ALL their ERP, SCM, CRM, and, of course, Web Servers are from a single vendor. Though we hate to repeat this but have they ever heard of something called "vendor lock-in".

Secondly, the report states that Microsoft has control over release cycles AND VULNERABILITY DISCLOSURES. Do they intend to say that the "days of risk" has been significantly affected by the fact that the vendor has control as to when the vulnerability will be disclosed?

A little later comes:
"Another factor which helps Microsoft in terms of average days of risk is that Microsoft strongly encourages a "responsible disclosure" policy - that is, the company attempts to carefully coordinate vulnerability announcement with fix announcement and actively build relationships with new security researchers."

It does seem that the report is trying to explain that the companies buying the Microsoft products are supposed to work closely with Microsoft to ensure that the vulnerability announcement and fix announcements are as close as possible to ensure that the "days of risk" are kept to a minimum. We sincerely hope that we got this one wrong.

Though a lot more can be analyzed in the report, it does appear that "independent" research seems to have been done (or should we say, written) by people who think that Enterprise IT Heads are a bunch of fools who have all the time on earth to read through tones of pages of deceptive analysis.

Source.

More in Tux Machines

Linux Foundation: Open Source Programming and DevOps Jobs Plentiful

Open source can help you make money, especially if you have skills in programming or DevOps, which is emerging as one of the hottest areas of interest for hiring managers seeking open source admins and developers. That's according to the latest Open Source Jobs Report from the Linux Foundation, which is out this week. Read more Also: The 2016 Open Source Jobs Report: Companies Hungry for Professional Open Source Talent

Basho Open Sources Some Bits

Leftovers: Ubuntu

  • The Simply Ubuntu Desktop
    Over on Flickr, fosco_ submitted this simple Ubuntu desktop, with just a few things tweaked for a cleaner experience. Like we’ve said, sometimes less is more, and this desktop makes good use of a few widgets to make a great UI even better.
  • HP Linux Imaging and Printing 3.16.5 Supports Ubuntu 16.04 LTS and Debian 8.4
    The team of developers behind the HPLIP (short for HP Linux Imaging and Printing) project, announced a few moments ago the availability of the fifth maintenance build in the 3.16 stable series of the software. For those of you who are not in the loop, HP Linux Imaging and Printing is an open-source initiative to bring the latest HP (Hewlett-Packard) printer drivers to GNU/Linux operating systems. The software has a pretty active development team working behind it, releasing maintenance builds at least once a month.
  • Convergence delayed: Unity 8 won’t be the default desktop in Ubuntu 16.10
    Canonical’s vision of convergence—a single, highly adaptive environment that spans mobile and desktop uses—has been delayed yet again. The Unity 8 desktop and Mir display server, which are key to that vision, won’t be used by default in Ubuntu 16.10, according to discussion in the Ubuntu Online Summit.
  • Questions and answers: Ubuntu bq tablet
    After Jack Wallen's recent review of the bq Aquaris M10 tablet, he was hit with a number of questions about the tablet. Jack addresses some of those questions to help you decide if the Ubuntu tablet is a worthy investment.

Bufferbloat Is Still Being Fought In Linux Kernel, Another Big Improvement Queued

Bufferbloat is the excess buffering of packets resulting in high latency, jitter, and lower network throughput. There's been efforts to battle bufferbloat within the Linux kernel going back a long time while this week another new patch has surfaced. A Phoronix reader pointed out to us a patch that's now been queued up in net-next for Linux 4.7 and could end up being back-ported to Linux stable releases. Read more Also: Watch why Linus Torvalds says Linux is the best option for career building