On CHOW: Holiday side dishes
BNET Business Network:
BNET
TechRepublic
ZDNet

February 28th, 2006

Vulnerability statistics for Mac and Windows

Posted by George Ou @ 2:40 am

Categories: Security

Tags:

In Focus » See more posts on: Apple Security

In yesterday's article "Is Mac OS as safe as ever", Joris Evers poses the age old question if Mac OS security is myth or reality.  I decided to settle this once and for all with some hard numbers from the independent security research group Secunia along with the number of CVE issues for Microsoft Windows XP and Mac OS X within the last two years.

Before I post the data, I want to make a few things clear since I keep getting the same questions and accusations every single time I post data on vulnerability statistics.

  • When visiting the Secunia links I provide in this blog, please DO NOT quote me on the number of advisories for a particular OS and blast me for getting the numbers wrong.  I am NOT counting advisories; I'm counting the actual number of vulnerabilities.  There are many advisories that contain multiple vulnerabilities and CVE IDs.  Sorry for the shouting, but I get about 10 of these "I don't count the same number of issues" every time.
  • No matter what some people may say, vulnerability ratings from Secunia are a valid measurement of security risk.  If we can't count the number of actual security vulnerabilities (with severity and patch status in mind), what can we count?
  • There seems to be a cavalier attitude that a vulnerability is not a problem if it hasn't been widely hacked yet.  The truth is that professional hackers don't want notoriety because it's bad for business.  Before Microsoft's infamous WMF vulnerability was infamous because of all the press coverage, it sold on the black market for $4000.  Nothing kills a money maker in the digital underworld faster than public exposure.
  • There will always be those who say vulnerabilities are only "theoretical".  Anyone who feels this way should leave their computers unpatched for all "theoretical" problems and post their email and IP address in talkback section and I'll be sure to forward a copy to the hacker forums.  I'm sure it probably won't be a problem since the problem is only "theoretical".
  • I make no claims on which operating system is better.  You look at the data and you be the judge.

Data gathered from Secunia:

How to read chart:

  • The three most severe levels of vulnerabilities from Secunia are analyzed in this chart.
  • The two less critical categories from Secunia were left out so the significant data will fit better on the screen.
  • The grayed out section represents the vendor with the worst security of the month.
  • Red font text represents unpatched vulnerabilities correlating to the degree of vulnerability.  For example in the month of February 2006, Apple's Meta data shell script execution flaw hasn't been fixed yet so it gets a red 1 in the extremely vulnerable column.

The data is clear, and Apple has a lot more vulnerabilities of every kind ranging from moderately critical to extremely critical.  While Windows had some months with more security disclosures, they are more spread out while Apple tends to release mega-advisories with dozens of vulnerabilities at a time.  There were seven months where Apple disclosed more a dozen or more highly critical vulnerabilities and August 2005 saw nearly three dozen of them.  One of the most severe zero day exploits for Mac OS X disclosed this month with a working proof-of-concept has yet to be patched so we'll have to wait and see how long it takes Apple to release a patch.

Microsoft on the other hand seems to let some moderately critical and even one highly critical vulnerability go unpatched for more than a year.  I've hammered Microsoft for this issue in the past and Microsoft has responded to me that they are clarifying some of these issues with Secunia because some of the unpatched vulnerabilities may be moot.  I'm still waiting for Microsoft's detailed explanation on these unpatched vulnerabilities.

George Ou is Technical Director of ZDNet. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 471 Talkback(s)
Security.
Qhoth Necro_z:

> If Unix and unix based systems are so invulnerable, why do
> *nix only data centers and server farms have security to
> rival some countries?

Because the data'... (Read the rest)
Posted by: bixbyru@... Posted on: 05/04/07 You are currently: a Guest | | Terms of Use
Sigh  Robert Crocker | 02/28/06
Sigh  crampy20 | 02/28/06
You are being biased and your conclusion is wrong!  ShadeTree | 02/28/06
Robert trust me Shade knows WRONG!!!  Laff | 02/28/06
Good one, Laff.  Judas I. | 02/28/06
I have raed a lot of your opinions so ...  ShadeTree | 02/28/06
If raeding my comments makes you think you know  Laff | 02/28/06
You took the first shot and then come back ...  ShadeTree | 03/01/06
I like playing and you are a game too me....:)  Laff | 03/01/06
I think...  nomorems | 03/01/06
Really  Robert Crocker | 02/28/06
If you can't refute the data then refute the ....  ShadeTree | 02/28/06
more unpatched?....  thelemite | 02/28/06
Shadetree, which OS has more unpatched...  mdsmedia | 02/28/06
Who Cares, the point is made, like it or not.  Cayble | 02/28/06
You did read it wrong...  zaphod@... | 03/03/06
Your being more then just a little disingenuous.  ShadeTree | 02/28/06
This is Easy . . .  joeldm | 02/28/06
No, that's being simple...  ajole | 02/28/06
Yes, but...  thatxbxtchxnicoll | 02/28/06
No, that isn't the argument either...  ajole | 02/28/06
You are the fanboi...  nomorems | 03/01/06
You are being simple as well...  zaphod@... | 03/03/06
Why just XP and not 9x/NT/2000?!  Bennopia | 03/03/06
Well, I have to admit......  Cayble | 02/28/06
Windows, Mac OS, Linux all easy to use  thunderdome1 | 03/01/06
linux is easier silly  Scott W | 03/01/06
HA!  thatxbxtchxnicoll | 03/01/06
Let's talk versatile ...  StupidScript | 03/01/06
there's a diference between infestations and vunerabilties  jumpa | 03/02/06
As are you  Fred Fredrickson | 03/02/06
I agree Fred  Bennopia | 03/03/06
PROOF: MAC USERS ARE GROUPIES  mashama@... | 03/01/06
If they're groupies we're ******!  Bennopia | 03/03/06
Sigh  nomorems | 03/01/06
Sigh aswell  tombalablomba | 02/28/06
Sigh a third time! happy  Mikael_z | 02/28/06
Oh my, this is just terrible  Letophoro | 02/28/06
I remember vaguely so please help me out here for as ec...  ju1ce | 02/28/06
But  Real World | 02/28/06
True  crampy20 | 02/28/06
BSD vs Mac OSX  ju1ce | 02/28/06
Not at all  Real World | 02/28/06
And the point...  ju1ce | 02/28/06
Windows ME has nothing to do with NT  jacarter3 | 02/28/06
Right...  Real World | 02/28/06
RE:Windows ME has nothing to do with NT  Scrat | 03/01/06
Scrat: Re: Windows ME has nothing to do with NT  Wolfie2K3 | 03/01/06
Couldn't agree more...  mdsmedia | 02/28/06
OS X dates back to 2000  george_ou | 02/28/06
so why not compare....  thelemite | 02/28/06
OK George, here's a better reason for why your numbers are wildy off  Letophoro | 02/28/06
shhh! you'll spoil George's....  thelemite | 02/28/06
RE: OK George, here's a better reason for why your numbers are wildy off  y-G | 03/01/06
NT/2000/XP dates back to 1995  Scott W | 03/01/06
NT was first released in 1993 (nt)  Fred Fredrickson | 03/02/06
There are lies, damn lies and statistics  MacGeek2121 | 02/28/06
moron  y-G | 03/01/06
Moron yourself.  timpin1@... | 03/02/06
Something funny I found on Secunia..  ju1ce | 02/28/06
George already said that...  ajole | 02/28/06
Fewer published exploits  george_ou | 02/28/06
haAHAHAHAHAHahahahah  An_Axe_to_Grind | 03/02/06
Not really  bladehawke | 02/28/06
CAN YOU EXPLAIN, GEORGE boy  theo_durcan | 02/28/06
Ignore this idiot Ou  j.m.galvin | 02/28/06
A rare post for you.  Anton Philidor | 02/28/06
Don't ignore him George...  nomorems | 03/01/06
Thats OK Pal...I'll Handle it from here...  Cayble | 03/01/06
Give it time  doctormoriarty | 02/28/06
And, would you not expect...  zkiwi | 02/28/06
???..!????!! ...wut the....@*&%@$#??  Cayble | 03/01/06
E for effort  timpin1@... | 03/02/06
My recommendation  b.d.hi | 02/28/06
was under the impression that Mac OS X  Protagonistic | 03/01/06
re: Give it time  wearthefoxhat | 03/01/06
Post your email and IP  george_ou | 02/28/06
Sure...  zkiwi | 02/28/06
He using Windows.. It's unhackable! (NT)  ju1ce | 02/28/06
Yes, I agree...  zkiwi | 02/28/06
I'm not trying to claim I can't be hacked without patching  george_ou | 02/28/06
George, George, George...  zkiwi | 02/28/06
Because he is saying he can't be hacked  george_ou | 02/28/06
MS thinks one of their vulnerabilities is a non-issue..  mdsmedia | 02/28/06
There is a huge difference between  Linux User 147560 | 02/28/06
ah, the "firewall" defense  thelemite | 02/28/06
You are right!  proprietary | 02/28/06
HAHAHAHAHAHAHAHAHA!!!!!!!!  NonZealot | 02/28/06
Nice counter argument! Bravo!  thelemite | 02/28/06
Post your email and IP  Protagonistic | 03/01/06
Can you explain...  Justin James | 02/28/06
So true... (NT)  ju1ce | 02/28/06
Phrasing.  Anton Philidor | 02/28/06
RE: Phrasing  Protagonistic | 03/01/06
Lucky?  thelemite | 02/28/06
Okay, but first you must do this...  NonZealot | 02/28/06
seems to me...  thelemite | 02/28/06
Are you comparing...  tic swayback | 02/28/06
Well, Can you explain...  b.d.hi | 02/28/06
Not too hard to explain  Justin James | 02/28/06
Like the sticker says  thatxbxtchxnicoll | 02/28/06
Thank you...you just explained it...  mdsmedia | 02/28/06
My experience too  NonZealot | 02/28/06
I suppose next you'll tell us....  thelemite | 02/28/06
I'll say that with confidence  NonZealot | 02/28/06
You are the lucky one.  nomorems | 03/01/06
no  y-G | 03/01/06
No Antivirus?  Crafty Badger | 03/02/06
Explain  crampy20 | 02/28/06
Don't count advisories, count vulnerabilities  george_ou | 02/28/06
And an Honesty Test for You too . . .  joeldm | 02/28/06
Funny but over the past few years I remember glancing  Laff | 02/28/06
I hear a lot of talk  Flying Pig | 02/28/06
Keep kicking that hornets nest, George  ejhonda | 02/28/06
Well since the ahem (3) so called "attacks" have resulted  Laff | 02/28/06
As I said above, give it time  doctormoriarty | 02/28/06
But that is not the subject here...it "IS" which is more secure.  Laff | 02/28/06
Yes, give it time  tic swayback | 02/28/06
Honest question...  thatxbxtchxnicoll | 02/28/06
No  george_ou | 02/28/06
Ahh  thatxbxtchxnicoll | 02/28/06
Not worried about number of exploits  NonZealot | 02/28/06
give it time indeed.  proprietary | 02/28/06
Everyone knows what you say even if they won't admit it  NonZealot | 02/28/06
Not being left alone  george_ou | 02/28/06
Wow, George! Are you sure?  ajole | 02/28/06
Sigh, the marketshare argument again  tic swayback | 02/28/06
DING DING DING!  NonZealot | 02/28/06
Web servers are relevant here  tic swayback | 02/28/06
Right, but  proprietary | 02/28/06
I'll give you a chance to take your post back  NonZealot | 02/28/06
The analogy addresses the logic of the argument  tic swayback | 02/28/06
Tic, not only that but as Letophoro points out...  thelemite | 02/28/06
Which version of Apache...  ye | 02/28/06
@ ye  thelemite | 03/01/06
yup, just like Apache 1.3.x vs IIs 4/5  thelemite | 02/28/06
Talk about groupthink!!!!  NonZealot | 02/28/06
We'll just have to agree to disagree.  thelemite | 02/28/06
If you want to be wrong, go ahead  NonZealot | 02/28/06
I think I see your problem...  thelemite | 02/28/06
The question isn't whether it is an analogy...  NonZealot | 02/28/06
It is an extremely appropriate analogy  tic swayback | 02/28/06
For the 20th time  NonZealot | 02/28/06
I think it is an applicable analogy...  brble | 02/28/06
Excellent post brble!  NonZealot | 02/28/06
Excellent post brble! (bolding corrected)  NonZealot | 02/28/06
Barble, stop making sense!....  thelemite | 02/28/06
NZ, are you seeing things?  tic swayback | 02/28/06
No, are you?  NonZealot | 02/28/06
Okay NZ  brble | 02/28/06
The nature of analogies  tic swayback | 02/28/06
Okay brbl  NonZealot | 02/28/06
NZ - Are Desktops and web servers share a commonality:  thelemite | 03/01/06
NZ - Desktops and web servers share a commonality:  thelemite | 03/01/06
I think many attitudes on both sides are flawed  brble | 02/28/06
Chocolate is better than Vanilla  corticus | 02/28/06
But this is exactly what some pc users are doing...  thatxbxtchxnicoll | 02/28/06
George, it's no contest - MAC wins!  thelemite | 02/28/06
linis dont work  doh123 | 02/28/06
hmmm... works for me  thelemite | 02/28/06
i manually did it...  doh123 | 02/28/06
weird...  thelemite | 02/28/06
Linewrap issues  tic swayback | 02/28/06
it must hate me...  doh123 | 02/28/06
that said..  mdsmedia | 02/28/06
try this link  thelemite | 02/28/06
MAC wins what?  proprietary | 02/28/06
yup, just like Apache marketshare eh?  thelemite | 02/28/06
uh no, but i agree there.  proprietary | 02/28/06
Don't personally know anyone on the Apache...  thelemite | 02/28/06
one hell of one product  proprietary | 02/28/06
Hmm yes.  friedcow | 03/02/06
Funny thing  timpin1@... | 03/02/06
Another meaningless comparison  Chad_z | 02/28/06
This is the point I keep making.. in many cases:  ju1ce | 02/28/06
Good point  tic swayback | 02/28/06
Well even that tic...  ju1ce | 02/28/06
I totally agree!  thatxbxtchxnicoll | 02/28/06
Actually  ITGuy04 | 02/28/06
Depends on where you look...  ju1ce | 02/28/06
Well Said  brble | 02/28/06
Well...  thatxbxtchxnicoll | 02/28/06
Another meaningless post  proprietary | 02/28/06
Another meaningless comparison  rscott22 | 02/28/06
Beach ball  timpin1@... | 03/02/06
Be careful about Dell  Bennopia | 03/03/06
Art of propaganda...  IAHawkeye | 02/28/06
Comparing his Zealotry to Windows and the Nazis...  ju1ce | 02/28/06
Read...Context....Of...Message  IAHawkeye | 02/28/06
Moot point  proprietary | 02/28/06
Sorry, linuxnode.  toadlife | 02/28/06
The meaning of context.  IAHawkeye | 02/28/06
Did you read the content of the link?  brble | 02/28/06
Apparently I lose then.....  IAHawkeye | 02/28/06
what?  proprietary | 02/28/06
and the windows flaw isn't?  thatxbxtchxnicoll | 02/28/06
need proof  doh123 | 02/28/06
Sorry George  CobraA1 | 02/28/06
hey.. be careful...  doh123 | 02/28/06
Although I may agree with you in some form...  ju1ce | 02/28/06
Read more carefully before blasting someone  Justin James | 02/28/06
re: Read more carefully before blasting someone  CobraA1 | 02/28/06
I think the Red number is the most important  nucrash | 02/28/06
True but  george_ou | 02/28/06
But what about length of time spent fixing?  thatxbxtchxnicoll | 02/28/06
No "but" about it  bidemytime | 02/28/06
Errata  bidemytime | 02/28/06
OS X has the extemely critical unpatched vulnerability now  george_ou | 02/28/06
But it DOES require some user interaction.  thatxbxtchxnicoll | 02/28/06
Though I hate to defend George  nucrash | 03/01/06
It requires no user interaction  timpin1@... | 03/02/06
And how long has that Mac problem been public?  bidemytime | 03/03/06
their loss  CobraA1 | 02/28/06
True but  mdsmedia | 02/28/06
8 Days and counting  nucrash | 03/01/06
Stop the counter!  tic swayback | 03/01/06
8 Days, Could be better.  nucrash | 03/02/06
businesses and testing  Mr_Dave | 02/28/06
Vulnerabilities are easier to find with source code  LittleGuy | 02/28/06
You forgot to say...  zkiwi | 02/28/06
Yes, I was going to fix the Linux kernel...  Anton Philidor | 02/28/06
*sigh*  zkiwi | 02/28/06
Louche way to agree with me.  Anton Philidor | 02/28/06
We don't agree  zkiwi | 02/28/06
George, here are the hard facts:  ITGuy04 | 02/28/06
LOL, learn to count actual vulnerabilities  george_ou | 02/28/06
So, you admit you're lying  ITGuy04 | 02/28/06
Very sad  george_ou | 02/28/06
Obvious question that must be asked  tic swayback | 02/28/06
If I do that, I'll have to add stuff for Apple too  george_ou | 02/28/06
Isn't IE a part of Windows where Safari is well not?  Laff | 02/28/06
No Laff  NonZealot | 02/28/06
People don't do that though  george_ou | 02/28/06
Then you need to be accurate  tic swayback | 02/28/06
So I should use IE on Mac?  nucrash | 03/01/06
Be fair  tic swayback | 02/28/06
why do I read this whole forum before I read this post?? NT  mdsmedia | 02/28/06
George and his fuzzy numbers again  supoman | 03/01/06
Proves what I've said about marketshare  NonZealot | 02/28/06
Could also be...  thatxbxtchxnicoll | 02/28/06
Marketshare means nothing  ITGuy04 | 02/28/06
You have the right to be...  NonZealot | 02/28/06
erm.. sorry to prove you wrong but...  thatxbxtchxnicoll | 02/28/06
You're wrong  ITGuy04 | 03/01/06
No, NZ, you say it because...  mdsmedia | 02/28/06
here's a question for the Mac/*nix crowd  nECrO_z | 02/28/06
Again the questions is not "IF" there are vulnerabilities in any given OS  Laff | 02/28/06
I think a much more accurate test of this...  thatxbxtchxnicoll | 02/28/06
excellent points all  nECrO_z | 02/28/06
That was my point  nECrO_z | 02/28/06
Ha!  thatxbxtchxnicoll | 02/28/06
Don't underestimate the patch process, it's very painful  george_ou | 02/28/06
I agree, but the article compares....  mdsmedia | 02/28/06
Awesome post! (NT)  ju1ce | 02/28/06
Funny you'd ask....  ProFab_z | 02/28/06
????  nECrO_z | 02/28/06
Thank you for some common sense  george_ou | 02/28/06
Erm, biased a bit?  thatxbxtchxnicoll | 02/28/06
Please show me every message..  mdsmedia | 02/28/06
Here are some answers...  pete-f@... | 03/01/06
Because places that require high security...  The King's Servant | 03/02/06
No, but you need to get a clue  george_ou | 03/02/06
No OS is 100% safe, but  MacGeek2121 | 04/07/06
Security.  bixbyru@... | 05/04/07
innumeracy  dennispocket | 02/28/06
Doth Protest Too Much  Harry Bardal | 02/28/06
No, this is new  george_ou | 02/28/06
Respond to my Point  Harry Bardal | 02/28/06
It's simple  george_ou | 02/28/06
6 Years  Harry Bardal | 02/28/06
Oh snap!  tic swayback | 02/28/06
Um, I can!!  NonZealot | 02/28/06
Me too  george_ou | 02/28/06
Here's a Point  Harry Bardal | 02/28/06
Responses all around  tic swayback | 02/28/06
Even with all those things  thatxbxtchxnicoll | 02/28/06
In response to tic  NonZealot | 02/28/06
I think that's Harry's point  tic swayback | 02/28/06
Tic: Harry's point  NonZealot | 02/28/06
Great argument for buying a Mac  tic swayback | 02/28/06
tic, I agree!  NonZealot | 02/28/06
Except that Security Through Obscurity isn't why Unix is secure  joeldm | 02/28/06
Paraphrasing your argument.  Anton Philidor | 02/28/06
No Thanks  Harry Bardal | 02/28/06
But Harry!  tic swayback | 02/28/06
tic  Anton Philidor | 02/28/06
Nonsense or what?  duksis | 02/28/06
George, could you please tell me why...  Benton Rich | 02/28/06
Because the last 2 years is relevant  george_ou | 02/28/06
I suppose...  Benton Rich | 02/28/06
Because the further back he goes the more the UGLY ms insecurity  michael_t | 02/28/06
So what's more important to you?  george_ou | 02/28/06
I base my descisions on past experience  kbeaumont | 02/28/06
It's disappointing, but your experience doesn't fit..  mdsmedia | 02/28/06
If that's your logic.....  tic swayback | 02/28/06
The last 2 years is relevant  george_ou | 02/28/06
Here's a better idea  tic swayback | 02/28/06
OS X still loses  george_ou | 02/28/06
Better, but I'm still not convinced it's fair  tic swayback | 02/28/06
Interesting, George....you claim...  mdsmedia | 02/28/06
why, George? Do they support your arguments? NT  mdsmedia | 02/28/06
That's why you're hammering ONE vulnerability in OSX?  mdsmedia | 02/28/06
Only serious FOOLS refuse to look and learn  michael_t | 02/28/06
WINNER! WINNER! WE HAVE A WINNER!  thelemite | 03/01/06
Perhaps, or perhaps not  Benton Rich | 03/01/06
Looks simple enough to me, why all the whining?  No_Ax_to_Grind | 02/28/06
Name calling Bit?  Robert Crocker | 02/28/06
Name? No, more like a label. happy  No_Ax_to_Grind | 02/28/06
If it wasn't for the FUD they were spreading...  NonZealot | 02/28/06
you know, for a "nonzealot" you sure are biased.  thatxbxtchxnicoll | 02/28/06
I thinks he's given up on the Non part....:)  Laff | 02/28/06
so it seems  thatxbxtchxnicoll | 02/28/06
Hehe, not given up at all!!  NonZealot | 02/28/06
rotflmfao @ you  thatxbxtchxnicoll | 02/28/06
statistics schmatistics.....  thelemite | 02/28/06
are you upset No-Ax?? NT  mdsmedia | 02/28/06
actually,  Robert Kohlenberger | 03/01/06
Useless discussion since XP is going away in  michael_t | 02/28/06
Is XP Going Away?  Kelmon | 03/02/06
George, please provide me a link  Monkey_MCSE | 02/28/06
I clearly stated this in blog  george_ou | 02/28/06
So Basically, what you're saying is...  Monkey_MCSE | 02/28/06
This is a joke right?  george_ou | 02/28/06
He asked where the numbers came from...  mdsmedia | 02/28/06
Pathetic attempts  george_ou | 03/01/06
The problem with George's method  berck | 02/28/06
Well said, and thank you!  zkiwi | 02/28/06
Clearly not the only problem  Richard Flude | 02/28/06
Don't bundle security advisories then  george_ou | 02/28/06
Be fair  tic swayback | 02/28/06
Wow  berck | 02/28/06
Same applies to both OSes  george_ou | 02/28/06
What?  tic swayback | 02/28/06
The advisories are categorized by Secunia  george_ou | 02/28/06
Don't blame Secunia  tic swayback | 02/28/06
I am being fair  george_ou | 02/28/06
But that's not fair!  tic swayback | 02/28/06
You can't break it down like that  george_ou | 02/28/06
That's going to take a lot more work on your part then  tic swayback | 02/28/06
Multiple vuneralbilites per advisory  berck | 02/28/06
I hate to split hairs but...  mdsmedia | 02/28/06
The same thing applies to Windows  george_ou | 02/28/06
Realization dawns?!?  Robert Crocker | 03/01/06
There are lies, d@mn lies,  georgep_z | 02/28/06
I don't really care WHAT the chart says  BitTwiddler | 02/28/06
and if you had to guess...  thatxbxtchxnicoll | 02/28/06
Really? Then you need to figure out what you're doing wrong  george_ou | 02/28/06
you're assuming he's not a consultant right George?  Monkey_MCSE | 02/28/06
No, I use to work in Enterprise too  george_ou | 02/28/06
re-read what i said George...  Monkey_MCSE | 02/28/06
George Ou is a Complete Wack Job!  joeldm | 02/28/06
what about a genuinly secure OS  jtoppi | 02/28/06
OK, now that we're done whining . . .  CobraA1 | 02/28/06
Will pc & mac/*nix users ever  thatxbxtchxnicoll | 02/28/06
What George and Others Like Him Don't Get . . .  joeldm | 02/28/06
LOL I love the analogy happy  mdsmedia | 02/28/06
Thanks! That's the issue: Vulnerability vs Infection!  joeldm | 03/01/06
George Ou is ignorant to call this an "extreme" vulnerability  AWolfe_II_z | 02/28/06
MAC vs WIN  TN-Limey | 02/28/06
lol they would...  mdsmedia | 02/28/06
There's the point  TN-Limey | 03/01/06
Ou Has Learned He Can Get Lots of Hits If He Says Ignorant BS about the Mac  joeldm | 02/28/06
so nothings perfect?  psimpsongore | 02/28/06
So this isn't a valid study or topic?  george_ou | 02/28/06
It is a fact if we use your numbers {NT}  thatxbxtchxnicoll | 02/28/06
These aren't 'my' numbers  george_ou | 02/28/06
Well according to what I'm looking at...  Monkey_MCSE | 02/28/06
Learn to count monkey  george_ou | 02/28/06
Not implying that you made them up exactly...  thatxbxtchxnicoll | 02/28/06
So we should just go by your "personal experience"?  george_ou | 02/28/06
no, but  thatxbxtchxnicoll | 02/28/06
NO, George!!  mdsmedia | 02/28/06
that depends...  mdsmedia | 02/28/06
Yes, but...  tangent001 | 02/28/06
Want to bet?  Randy Smith | 03/01/06
No George YOU'RE WRONG AGAIN!  joeldm | 03/01/06
moral of the story  glocks out | 02/28/06
new test  glocks out | 02/28/06
I accept your test!!  NonZealot | 02/28/06
And do these numbers come from...  zkiwi | 02/28/06
Try...  Brich | 02/28/06
Not Possible.  thatxbxtchxnicoll | 02/28/06
To all those that replied  NonZealot | 02/28/06
funny thing..  thatxbxtchxnicoll | 03/01/06
i guess so  glocks out | 03/01/06
Opposing views not in reality  bobhog | 02/28/06
Always interesting when you challenge conventional wisdom  george_ou | 02/28/06
About time  bobhog | 02/28/06
George, if you have no bias...  mdsmedia | 02/28/06
and if you bothered to actually read any of it...  thatxbxtchxnicoll | 02/28/06
"Data don't lie"  tic swayback | 02/28/06
It's the user AND the OS that make a system secure or insecure!  ruprick_z | 02/28/06
Pavlov's Dog  D. T. Schmitz | 02/28/06
about statistics  CobraA1 | 02/28/06
A Big Sigh  cuppachino | 02/28/06
The real deception here  tangent001 | 02/28/06
Don't get started with Firefox  george_ou | 02/28/06
From Secunia:  tangent001 | 02/28/06
I've already addressed that  george_ou | 03/01/06
You were told wrong  george_ou | 03/01/06
What was your advice then?  ruprick_z | 03/01/06
You're right  slantyyz | 03/01/06
a few things . . .  CobraA1 | 03/01/06
George Ou should be banded from writing  Bob Trikakis | 03/01/06
Method  D. T. Schmitz | 03/01/06
If only  tic swayback | 03/01/06
I agree  rudeshock_z | 03/01/06
Keep writing George!  Smarty_Pantz | 03/02/06
The biggest vulnerability  slantyyz | 03/01/06
PROOF: MAC USERS ARE GROUPIES  mashama@... | 03/01/06
A lot of the Vulnerablities on Mac OS X  blidd | 03/01/06
Use what you want- but backup your data...  TracyF | 03/01/06
Lies, damned lies, and statistics  Doug K | 03/01/06
DOS  proprietary | 03/01/06
Depends on what's being denied  Doug K | 03/01/06
Hmmm, George Did you cash the check yet?  Randy Smith | 03/01/06
You may have MCSE...  ianbetteridge | 03/01/06
Ratio 150,000-3 = Stupid Nonsense  Sid_video | 03/01/06
Required Reading  tic swayback | 03/01/06
Sensationalism in news  thatxbxtchxnicoll | 03/01/06
oh, and..  thatxbxtchxnicoll | 03/01/06
Advisory count is very misleading  george_ou | 03/01/06
So is your method  berck | 03/01/06
It's a hell of a lot more accurate than counting advisories  george_ou | 03/01/06
Maybe  berck | 03/01/06
I'm saying it's not perfect, but the most accurate  george_ou | 03/01/06
It's still flawed and arbitrary  tic swayback | 03/01/06
Sorry  berck | 03/01/06
I do believe that I said  thatxbxtchxnicoll | 03/01/06
ALL of these stats are misleading - security depends on a LOT of factors  CobraA1 | 03/01/06
The whole story  Unemployed IT Guy | 03/01/06
MAC, WIN and LINUX  TN-Limey | 03/01/06
Thanks George  msftshiller | 03/01/06
another one dead on.  proprietary | 03/01/06
Totally wrong  plokoonpma | 03/01/06
Just one question.  MacGeek2121 | 03/01/06
What a moron...  meseeu | 03/01/06
Vulnerability statistics for Mac and Windows  Protagonistic | 03/01/06
LAME  Kid Icarus-21097050858087920245213802267493 | 03/01/06
Time to update that chart George  tic swayback | 03/01/06
That is not a correction  george_ou | 03/01/06
But now that the numbers have changed....  tic swayback | 03/02/06
Figures don't lie but liars can figure...  Dr. Dubious | 03/01/06
Look at Linux  richdave | 03/01/06
misleading.  proprietary | 03/02/06
Apple just pached only known vulnerability  mpredmond | 03/01/06
Better?  dscherm | 03/01/06
Patch as Patch Can  D. T. Schmitz | 03/01/06
The use of vulnerability counts  mysidia | 03/01/06
George Ou - Microsoft Information Minister!  fernando.cassia@... | 03/02/06
Read this before you poll  george_ou | 03/02/06
George Ou is an Intellectually Dishonest Coward  joeldm | 03/02/06
I'm not sure...  tic swayback | 03/02/06
I Think He Knows and Enjoys the Attention, Not the Logic!  joeldm | 03/02/06
Useless?  VonKraut | 03/02/06
The only problem...  sysedco | 03/13/06
And then more problems...  Blade Blade | 03/14/06
Hey what about Commodore 64 vulnerabilities??!  Brakiss | 03/02/06
Children, children  energy83 | 03/02/06
ZDnet refutes Ou's "REPORT"  An_Axe_to_Grind | 03/02/06
WINDOW of vulnerability  Sxooter_z | 03/02/06
One problem with the data...  Mercat | 03/03/06
There's more than just Windows XP!  Bennopia | 03/03/06
Only did XP Pro and Home for a reason...  Mercat | 03/03/06
Not to mention...  Mercat | 03/03/06
As far as I'm concerned...  ancient_user | 03/03/06
Attack: Aim? X=XP on security.  Paul Arnett | 03/04/06
misuse of abbreviation "X"  JetJaguar | 03/05/06
21% Windows bug unpatched  luckybit | 03/06/06
Do all these statistics REALLY mean anything?  jbkendrick | 03/18/06
Mac = 14 Os Upgrades? Windows = 1 ?  peacheasy | 03/22/06

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

Click Here
advertisement

Recent Entries

Top Rated

    advertisement

    Archives

    ZDNet Blogs

    White Papers, Webcasts, and Downloads

    SmartPlanet

    Click Here