 |
|  |
 |
|
Asher
|
 |
Calgary, Alberta
Nov 1999 time: 22:28
|
|
Draw your own conclusions. 
http://www.wininformant.com/Article...ArticleID=39231
quote: Linux Not as Secure as Windows Server
Curiously, this news will come as a surprise to some people, but according to a report from the security experts at mi2g, open-source poster child Linux is losing the security fight--big time--to Windows Server. Yes, you read that right: In May 2003 alone, Linux-based corporate and government systems experienced 19,208 successful breaches worldwide, whereas similarly oriented Microsoft Windows Server systems suffered only 3801 breaches. During this time period, more than 75 percent of all server-based breaches occurred on Linux systems; Windows systems were responsible for just 15 percent of breaches. Furthermore, the reports says that Windows-based systems were far more resilient than Linux-based systems during the Iraq war months from March to May 2003, a time of increased hacking activity. mi2g, which has been tracking server attacks since 1995, now oversees a database that contains more than 220,000 individual attacks and more than 7000 hacker groups. So why are Linux servers more easily compromised? The security experts quote several primary reasons: First, most Linux servers are improperly configured and don't come with decent default security configurations. Second, the open-source community doesn't have a coherent "trustworthy computing" initiative. Third, Linux is a target because of its increasing popularity in the server world. And, fourth, Frank Stallone. In other words, everything I've been saying about Windows, Linux, and security not only is true but is evolving in a wonderfully predictable way. Shouldn't we stop all the bogus "Windows isn't secure" baloney when a far less secure competitor is just waiting to be compromised? |
|
|
|  |
 |
|  |
 |
|  |
 |
|  |
 |
|
Asher
|
 |
Calgary, Alberta
Nov 1999 time: 22:28
|
|
quote: According to a new Aberdeen Group report, open-source solution Linux has surpassed Windows as the most vulnerable OS, contrary to the high-profile press Microsoft's security woes receive. Furthermore, the Aberdeen Group reports that more than 50 percent of all security advisories that CERT issued in the first 10 months of 2002 were for Linux and other open-source software solutions. The report muddles the argument that proprietary software such as Windows is inherently less secure than open solutions. And here's another blow to the status quo: Proprietary UNIX solutions were responsible for just as many security advisories as Linux in the same time period. Could Windows be the most secure mainstream OS available today?
"Open-source software, commonly used in many versions of Linux, UNIX, and network routing equipment, is now the major source of elevated security vulnerabilities for IT buyers," the report reads. "Security advisories for open-source and Linux software accounted for 16 out of the 29 security advisories--about one of every two advisories--published for the first 10 months of 2002. During this same time, vulnerabilities affecting Microsoft products numbered seven, or about one in four of all advisories."
The stunning report makes several claims that seem to fly in the face of widely accepted beliefs. First, the Aberdeen Group says that Windows-based Trojan horse attacks peaked in 2001, when CERT released six such advisories, then bottomed out this year, when CERT didn't issue any alerts. However, Trojan horse-based attacks on Linux, UNIX, and open-source projects jumped from one in 2001 to two in 2002. The Aberdeen Group says this information proves that Linux and UNIX are just as prone to Trojan horse attacks as any other OS, despite press reports to the contrary, and that Mac OS X, which is based on UNIX, is also vulnerable to such attacks. Even more troubling, perhaps, is the use of open-source software in routers, Web servers, firewalls, and other Internet-connected solutions. The Aberdeen Group says that this situation sets up these devices and software products to be "infectious carriers" that intruders can easily usurp.
According to the Aberdeen Group, the open-source community's claim that it can fix security vulnerabilities more quickly than proprietary developers can means little. The group says that the open-source software and hardware solutions need more rigorous security testing before they're released to customers. This statement is particularly problematic because many Linux distributions lack the sophisticated automatic-update technologies modern Windows versions contain. |
|
|
|  |
All times are GMT. The time now is 05:28. Apolyton Time is 00:28. |
top of page
|
| archivepost |
|
Forum Rules:
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
|
HTML code is ON
vB code is ON
Smilies are ON
[IMG] code is ON
|
|
|
|
|
|