On CBS MoneyWatch: Is There Gold in Fort Knox?
BNET Business Network:
BNET
TechRepublic
ZDNet

December 20th, 2007

Mac versus Windows vulnerability stats questioned

Posted by Ed Burnette @ 6:15 am

Categories: Apple, General, Microsoft

Tags: Apple Macintosh, Windows Vulnerability, Apple Mac OS X, Microsoft Windows, Operating Systems, Software, Apple Mac OS, Ed Burnette

For his first post on the Zero Day blog after the departure of Ryan Naraine, George Ou has stirred up a hornets nest by suggesting that Macs have far more security holes than Windows PCs. No stranger to controversy, George compiled a bunch of security advisory figures from Secunia and reached this conclusion:

So this shows that Apple had more than 5 times the number of flaws per month than Windows XP and Vista in 2007, and most of these flaws are serious. Clearly this goes against conventional wisdom because the numbers show just the opposite and it isn’t even close.

I’m sure this will surprise no one but a lot of people disagreed with George’s findings. As I write this there are over 300 comments, most of which are negative. Ignoring the knee-jerk “That can’t be true” reactions however, a number of posters have raised what seem to be legitimate concerns with the analysis. In the interest of balance I wanted to highlight a few of them.

buddhistMonkey pointed out that George seemed to be ignoring this warning on Secunia’s web site:

“PLEASE NOTE: The statistics provided should NOT be used to compare the overall security of products against one another. It is IMPORTANT to understand what the below comments mean when using the statistics, especially when using the statistics to compare the vulnerability aspects of different products.”

RestonTechAlec calls the comparisons misleading, giving two examples of bulletins that are treated as equals but are far from it:

Two examples from December’s list illustrate this. First, for OS/X:

“Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value.”

What type of user uses tcpdump? Is this a concern? Yes, it is, but ask yourself– for who?

Now, a Vista detail:

“Buffer overflow in Microsoft DirectShow in Microsoft DirectX 7.0 through 10.0 allows remote attackers to execute arbitrary code via a crafted (1) WAV or (2) AVI file.”

You can catch a WAV or AVI file surfing with IE. So this is also a concern, but for who? Probably everybody.

whooda (don’t you just love these aliases?) said the search criteria was flawed:

From your very link in the article, you are ONLY reporting vulnerabilities for Microsoft Windows XP Professional.

The problem being that you are only reporting CVEs for Windows for the XP Professional and Vista products (leaving out the Home Edition and Server products). However, you are reporting all OS X CVEs, including any for 10.0, 10.1, 10.2, 10.3, and their respective SERVER products because Secunia doesn’t provide a finer-grained OS X search.

On top of that, Apple also posts security updates for third-parties that can effect OS X or other OSes.

Francois (f.r) looked at the reports in more detail and noticed several discrepancies:

The OS X columns contains 7 duplicates…

The following 20 reports in the OSX column have a CVE that says “reserved” with no mention of the affected OS or product. How do you know those are OS X flaws ?…

There are 16 reports in the OS X column for the Sun JRE/JDK. However, Sun does not provide a JVM for OS X. Indeed, the corresponding CVE reports don’t list OS X as an affected OS. Why are those reports in the OS X column ? …

CVE-2007-3504 is described as Windows-only. However, it appears in the OS X column. Why ?

CVE-2007-3756, CVE-2007-3758 also affect Safari on Windows (and iPhone) but apparears only in the OS X column. Why ?

I am curious to know why you listed the following 7 SquirelMail vulnerabilities in the OS X column. This product is not bundled with OS X. And since it’s pure PHP code, those are surely present on Windows as well. …

Same question for the 7 MySQL vulns …
There are also 8 PHP vulns …

The OS X column also contains Ruby on Rails vulns. And Safari 3 vulns (which Apples lists under OS X AND Windows but not you). And Adobe Flash player.

It looks like to me that you did not consider the same type of usage. One one hand, a Windows desktop, with no third-party software. On the other, a Mac Server loaded with PHP, SquirelMail, Ruby on Rail and MySQL. Obviously, you will find more security holes in the second case.

In all fairness, there were a few posters that supported George’s claims. My favorite was from tomhoffman, who wrote:

You probably won’t see this on a Mac commercial!

Ed BurnetteEd Burnette is a professional developer and author of several articles and books about computing including Hello, Android: Introducing Google's Mobile Development Platform, 2nd Edition. For disclosure of Ed's industry affiliations, click here or to view his full profile click here.

Email Ed Burnette

Subscribe to Dev Connection via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 65 Talkback(s)
RE: Mac versus Windows vulnerability stats questioned
What I find interesting and a part that George left out
about the "hacked" MacBook...the organizers had to
relax the rules as it remained secure for 2 whole days.
To drum up "news" and sit... (Read the rest)
Posted by: lexicon5 Posted on: 01/09/08 You are currently: a Guest | | Terms of Use
Exactly, it was a poor comparison...  el1jones | 12/20/07
There is nothing meaningful that can be drawn from these comparisons.  ye | 12/20/07
agree + 1 NT  tombalablomba | 12/20/07
But it is very useful anyway  shis-ka-bob | 12/21/07
agree +2 NT  TechExec2 | 12/21/07
That "warning" is talking about the comparison of Advisories, not CVEs  georgeou | 12/20/07
Inveigle  Win3.1 | 12/20/07
GeorgeOu you are no Ryan Naraine.  The_Nutty_Zealot | 12/20/07
agree +1 NT  tombalablomba | 12/20/07
agree +2 NT  TechExec2 | 12/21/07
And yet, George,  msalzberg | 12/20/07
Message has been deleted.  ego.sum.stig@... | 12/23/07
And yet you can't even accurately compare CVE's  Letophoro | 12/21/07
Hastily thrown together???  dsw0@... | 12/20/07
Of course  Qbt | 12/20/07
Bingo! (nt)  ye | 12/20/07
but then again  tombalablomba | 12/20/07
Translation  frgough | 12/20/07
But if at least 25% of the list is wrong..  msalzberg | 12/20/07
I totally agree. Nice post.  NonZealot | 12/20/07
Coming from a Kool-Aid-drenched MS fanboys  deaf_e_kate | 12/20/07
I can't wait  tombalablomba | 12/20/07
Not just flame bait  frgough | 12/20/07
One of the funniest (maybe saddest) things..  msalzberg | 12/20/07
who did? (nt)  doh123 | 12/20/07
Sorry, I don't understand your question. NT  msalzberg | 12/21/07
Defend the Queen at its finest!  Scrat | 12/20/07
What evidence?  msalzberg | 12/20/07
re: What evidence?  M.R. Kennedy | 12/20/07
Is it?  msalzberg | 12/20/07
Very shoddy reasoning  MarcB_z | 12/20/07
Attack the evidence.... How unfair can you get! - NT  raycote | 12/20/07
What is ironic is that Secunia used to be the battle cry for ABMers  NonZealot | 12/21/07
Secunia is still fine  shis-ka-bob | 12/31/07
RE: Mac versus Windows vulnerability stats questioned  Todd Papke | 12/20/07
RE: Mac versus Windows vulnerability stats questioned  Harvey Lubin | 12/20/07
There are OS X exploits in the wild  NonZealot | 12/20/07
List them  Martin Pilkington | 12/20/07
Don't bother  ninhead79 | 12/20/07
well...  doh123 | 12/20/07
Ask and ye shall receive: here are the 150  NonZealot | 12/20/07
Umm, did you read that link?  msalzberg | 12/20/07
So you deny there are at least 150 exploits in the wild?  NonZealot | 12/20/07
OuiZealot is right: The user is the ultimate exploit  mdfischer | 12/21/07
Long answer:  msalzberg | 12/21/07
My apologies.  msalzberg | 12/20/07
That's cool, I've been snarky once or twice (or a thousand times)  NonZealot | 12/20/07
As much as we yell and scream at each other..  msalzberg | 12/20/07
I totally agree happy (nt)  NonZealot | 12/21/07
These are not OS/X vulnerabilities  shis-ka-bob | 01/02/08
RE: Mac versus Windows vulnerability stats questioned  smarty_pants | 12/20/07
Food for thought  SquishyParts | 12/20/07
Sux 2B (Y)Ou  Mike Cox, Sr. | 12/21/07
Thank you!!!  ninhead79 | 12/21/07
Wow, interesting article!!  NonZealot | 12/21/07
Message has been deleted.  ego.sum.stig@... | 12/23/07
No  ego.sum.stig@... | 12/28/07
Opinion  loujloujl@... | 12/21/07
Opinion  loujloujl@... | 12/21/07
ZDnet Cred  SquishyParts | 12/21/07
EVEN with corrections  JABBER_WOLF | 12/23/07
Try, try, try..  msalzberg | 12/23/07
Get over it already  otaddy | 12/29/07
does george ou get paid?  Akumal | 01/02/08
RE: Mac versus Windows vulnerability stats questioned  lexicon5 | 01/09/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here