The Daily Static
  The Daily Static
UF Archives
Register
UF Membership
Ad Free Site
Postcards
Community

Geekfinder
UFie Gear
Advertise on UF

Forum Rules
& FAQ


Username

Password


Create a New Account

 
 

Back to UserFriendly Strip Comments Index

Will MS ever learn? by imrambi2006-11-19 12:55:59
  one flaw i can see is how often by joecrouse2005-03-26 09:50:38
    There's also the difference between by Tars_Tarkas2005-03-26 12:12:23
      And then they quote the Forrester report by bwkaz 2006-11-19 12:55:59

(in the footnote, on page 3 of the PDF) by saying:

1 "Is Linux More Secure Than Windows" by Laura Koetzle, Forrester Research, covers some of the issues outlined in this paper well.

(Emphasis mine.) This report was debunked by the distros themselves, whose executive summary went like this:

GNU/Linux vendors Debian, Mandrake, Red Hat, and SUSE have joined together to give a common statement about the Forrester report entitled "Is Linux more Secure than Windows?". Despite the report's claim to incorporate a qualitative assessment of vendor reactions to serious vulnerabilities, it treats all vulnerabilities as equal, regardless of their risk to users. As a result, the conclusions drawn by Forrester have extremely limited real-world value for customers assessing the practical issue of how quickly serious vulnerabilities get fixed.

The Forrester report may have covered an issue (namely, "number of vulnerabilities in a time frame"), yes. However, that is not what either report was advertised as covering (overall security).

The actual data given by Forrester included "the average time for [what we classify as] critical vulnerabilities to be fixed". At first glance this looks like a good thing to be measuring. But it's not -- one issue is that Forrester classified the vulnerabilities themselves, and not all remote holes are automatically at the "extremely critical" rating (which is basically where Forrester put them, IIRC).

To be fair, this report did note some (not all!) of the shortcomings of the Forrester one. But when they talk in such glowing terms about such a flawed study when they first mention it, I start to wonder.

Also, how much different would this group's results have been if they'd chosen Perl instead of PHP? What about Python?

[ Reply ]

 

[Todays Cartoon Discussion] [News Index]

Come get yer ARS (Account Registration System) Source Code here!
All images, characters, content and text are copyrighted and trademarks of J.D. Frazer except where other ownership applies. Don't do bad things, we have lawyers.
UserFriendly.Org and its operators are not liable for comments or content posted by its visitors, and will cheerfully assist the lawful authorities in hunting down script-kiddies, spammers and other net scum. And if you're really bad, we'll call your mom. (We're not kidding, we've done it before.)