30 Comments(s). 1 Pages(s). Showing page 1. [ 1 ]

   #1. Posted at 09:37 AM on Jun 22nd 2007 Edit   Reply

How widely deployed is Vista relative to the others? Also, what is the count of "Undisclosed Vulnerabilities"?
collapse

   #18. Posted at 12:33 PM on Jun 22nd 2007 Edit   Reply

The security vulnerability counts for linux distributions include literally thousands of 3rd-party application packages that are available for installation. If you were to take those out, you would probably get a much different (and more accurate) picture.
collapse

   #8. Posted at 10:24 AM on Jun 22nd 2007 Edit   Reply

I'm not so sure, I mean I've been running vista for some time now and sure it may have all that security built-in (enough to annoy you at times) but I still don't think it as strong as they say they are. Just yesterday I did a virus scan and found a hole slew viruses ranging from worms to Trojans and of course the usual spyware. I'm running vista and latest mcafre software with the current virus defs.

But perhaps the reason it may so secure in their eyes is the fact that the OS is really unpredictable at the moment especially considering how applications just seem to freeze up every once in a while or the whole gui goes to basic whenever an application that apparently is not supported by the interface goes nuts.

And then there is the more obvious reason. Vista is new so it'll take some time figure out many of its major flaws and once those are found and they will be, the OS will return to it previous position.
collapse

   #2. Posted at 09:44 AM on Jun 22nd 2007, Edited at 09:52 AM on Jun 22nd 2007 Edit   Reply

collapse

   #29. Posted at 06:46 AM on Jun 24th 2007 Edit   Reply

So MS is saying that mimicking linux/OSX is starting to pay off then eh, good for them, pity that they did manage to include daft obvious holes and some shoddy issues regarding drivers and permissions forcing user to circumvent security to get things to run, negating the 'secure OS' concept.
collapse

   #17. Posted at 11:57 AM on Jun 22nd 2007 Edit   Reply

All the statistics are based on MSRC classifications, which are extremely conservative (as they should be). Take the animated cursor bug for example (MS07-017). MSRC labeled it a critical bug on Vista, but what effect the exploits have on Vista running in a default configuration? None. Protected Mode IE saved it. Of course, it’s possible (but really dumb) to turn off Protected Mode, so it’s a critical bug. I doubt other vendors would classify their own problems as conservatively, so looking at the numbers is far from an apples to apples comparison.
Along the same lines, I think Vista takes the right approach to security (even if some things like UAC aren’t the ideal solution). Basically, it assumes that there will be security holes in the code (it’s dumb to assume there won’t be any in any reasonably sized project), and it tries to limit the exploitability of those holes. ASLR, NX, /GS, UAC, Protected Mode IE (and hopefully other reduced privilege apps later), etc. make it hard to exploit any hole. It’s not going to be impossible, but I’d be very surprised if we see someone make it through all of those anytime soon. The new problems will probably be more social engineering hacks than technical.
collapse

   #12. Posted at 11:02 AM on Jun 22nd 2007 Edit   Reply

"fewer serious security vulnerabilities have been found "

Thats the key here. Thats not saying they dont exist, they just havent been "found".... yet.
collapse

   #20. Posted at 01:42 PM on Jun 22nd 2007 Edit   Reply

Six months isn't much to go on, but it's still a good sign. As to Linux' inherent insecurity, that has as much to do with build options as anything else. Still, I tire of hearing how secure Linux is vis a vis anything else.
collapse

   #9. Posted at 10:41 AM on Jun 22nd 2007 Edit   Reply

amusing, Apple says their OS is the most secure, MS thinks their OS is secure, and penguins think Linux is the best...surprise!
collapse
30 Comments(s). 1 Pages(s). Showing page 1. [ 1 ]
 
Name/Password: / Remember
Reply to:
[click to clear]

[RED] [GREEN]
[BOLD]
[ITALIC] [STRIKE]
[UNDERLINE]

Notice: All posts should abide by the rules, please.
Note: Ctrl-Enter submits the post. (In IE)
DThread keys: Click on a reply to position the blue bar. 'A'/'Z' move it up/down.
Jazztags: (they MUST be closed)
    r{ red }r     g{ green }g     /[ italic ]/     *[ bold ]*
    _[ underline ]_     -[ strike ]-     s[ sample ]s     o[ spoiler ]o  q[ (QUOTE) ]q