linux
linux

The Penguin bites back at Windows

The Linux-more-vulnerable-than-Windows debate rages on

James Middleton

Our postbag has been overflowing, following reports that certain distros of the Linux operating system suffered more security vulnerabilities than Windows last year.

Because all Linux distributions use the same kernel, figures cannot be aggregated for the open source OS. But readers have also pointed out that confusion has resulted from the fact that Linux distros typically ship with bundles of applications, which may also be prone to vulnerabilities.

Advertisement

According to the figures gathered from SecurityFocus's Bugtraq mailing list, mainstream Linux distros such as Mandrake 7.2, Red Hat 7.0 and Debian 2.2 had 33, 28 and 26 security vulnerabilities reported last year respectively.

This compares with a total of 24 security vulnerabilities reported for Windows 2000 - leading some commentators to argue that the Microsoft OS is more reliable than the least reliable Linux distros.

Bugtraq also reported that Solaris 7 and 8 tied with Redmond's score of 24 security bugs.

However, industry experts agreed with vnunet.com readers that the Bugtraq figues warrant careful examination as they include vulnerabilites in applications that ship with core operating systems.

Neil Barrett, technical director at security consultancy Information Risk Management, said: "Nine times out of ten, hackers break into a site through an application vulnerability. It's almost always the application packages that cause the problems."

One vnunet.com reader, Alex Roston, wrote in to say: "A Linux distribution already includes at least one webserver (and all the other packages an office might use, such as Netscape, Star Office and Evolution (a mail suite)... Your article fails to take into consideration the size of most Linux distributions. My Mandrake 7.1 distribution included 1500 packages, for a package/vulnerability ratio of about 55:1. I don't pay much attention to Windows distributions, but I suspect that the ratio of packages to vulnerabilities is much higher."

Tom Sightler, a senior network engineer, added: "With Linux distributions, the numbers do, in some cases, include vulnerabilities discovered in the OS, Sendmail, Apache, email clients, PostgreSQL, and hundreds of other programs that are included with the distribution."

Barrett said that when considering security vulnerabilities, you should always bear the applications in mind.

"The figures from the survey are probably correct," he said, "but people running Linux tend to be more switched on when looking for security bugs."

Reader Zach Younker said that a kernel versus kernel comparison would have been more appropriate. "The Linux operating system is comprised of hundreds of packages from various vendors.

"If you want to break it down you should do kernel vs kernel comparison. Comparing a complete operating system and all its programs to an operating system is just not fair," he said.

As many readers pointed out, it is also possible that because Windows is based on closed source code, the number of bugs reported are only the ones we know about. And while avoiding the Microsoft conspiracy theory, more vulnerabilities may have been reported in Linux because of its open source nature.

But Barrett also said that the severity of the vulnerabilities should be considered. "Some Microsoft errors are just trivial security problems like default passwords," he said. "I mean, how many times can you say 'Doh!' to that?"

If you have more to add to this topic, email us at feedback@vnunet.com.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Gartner slams Linux on the desktop

Windows is cheaper "most of the time" analyst says

Fans should 'weep' over Linux bugs

Or should they... Security reporting, it's all lies, damned lies and statistics

Controversy brews in Linux camp

Open source supporters refute claims that Windows has less vulnerabilities

Windows more secure than Linux?

Vulnerability tracker gives Windows cleaner bill of health than Open Source

Related whitepapers

Related jobs

Most watched

Xperia X1

Video Review: Sony Ericsson Xperia X1

First Looks Editor Ian Williams gets hands on with the Sony Ericsson Xperia X1

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

IT white papers

Search white papers

Top categories

Poll

Poll: Summer smartphones

Poll: Summer smartphones

Which smartphone will you be taking to the beach this summer?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

a padlock

Microsoft to plug security holes

Microsoft has given advance warning of a number of security...

Nokia handset

Top 10 articles, 10 July 09

No Nokia Android phone, ActiveX attacks and Google enters into...

Can Google beat Microsoft at its own game?

Google's announcement this week that it plans to step into...

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

Primary Navigation