Huddled Masses
You can do more than breathe for free...
Browse: Home / Hype Machine in Full Gear

Hype Machine in Full Gear

By Joel 'Jaykul' Bennett on 27-Mar-2007

Symantec’s 11th Internet Security Threat Report, released this week, discusses security and vulnerability issues from the last six months of 2006 and according to enterprise IT planet “Microsoft Windows had the fewest number of patches and the shortest average patch development time … Red Hat Linux ranks second, OS X third, and Solaris dead last.”

This comes on the heels of this post by Microsoft strategy director for security technology, Jeff Jones which shows Vista doing substantially better in it’s first three months than any other OS.

Don’t buy the hype.

Of the three months that Jeff Jones is comparing, Windows Vista has only been publicly available for one month — the first two months are the time it was available only on enterprise MSDN subscriptions. Although I was running it during that time, the scarcity of drivers and software that worked in Vista during that pre-public release made it very clear that this was not really a “launched” OS.

Buck back to the new report from Symantec — presumably no friend of Microsoft’s, and with a vested interest in making Windows sound frighteningly vulnerable. The new report ranks Microsoft first in their security chart, and that’s what the Enterprise IT article is touting.

However, despite having the “fewest number of patches and the shortest average patch development time” — patching vulnerabilities on average in three weeks — Microsoft Windows had 12 severe or high-priority vulnerabilities out of 39 total. Basically, 1/3 of the vulnerabilities discovered in Windows were considered high priority — even though on average Symantec only rated four percent of all vulnerabilities as high priority.

Although Mac OS X was ranked third according to the article, it had only 3 more vulnerabilities than Windows, and although on average they took nearly three times as long to respond, perhaps they can afford to take their time, since OS X had only one high priority vulnerability. Red Hat —which they ranked second based on their response time— had a whopping 208 vulnerabilities, but it still only had 2 that were considered high severity. All in all, it’s hard to justify ranking by patch time ;-) .

More interestingly…

To me, the most interesting thing in the report wasn’t mentioned in the article linked above: the United States not only has the highest number of bot command-and-control computers (40% of the worldwide total) but also accounted for more malicious activity than any other country (nearly 1/3 of all tracked activity), more spam email hosts, and more phishing hosts… in second place, China only accounted for 1/3 as much “malicious activity” as the US. Forget your notion that hackers are Eastern European malcontents: the United States accounts for 19 percent of the world’s Internet users, and 30% of malicious activity.

Another interesting point: worms are down from 75 to only 52 percent of the volume of malicious code … replaced by Trojans, which are up from 23 to 45% of the top malicious code threats. When it comes to actual infections, Trojans measure 60% while traditional “viruses” account for only 5% of all infections!

By the way, at what point do other countries start accusing the US of being a hotbed of international computer crime and demanding that we crack down on this stuff?

Similar Posts:

  • ShotGlass

Posted in Huddled | Tagged Huddled Masses

« Previous Next »

Lijit Search

Tags

.Net .Net 2008 Scripting Games Automation Bugs Design Development Funny Gadgets GeoShell GUI Huddled Masses Internet licensing Microsoft Modules My Software News Personal PInvoke Pipeline Politics PoshCode PoshConsole PowerBoots PowerShell PowerShell Functions PowerTips Rants Recommender Repository Scripting ShowUI Software Solutions Textile Tips User Group UserInterface WalkThrough WebHosting Windows 7 WordPress WPF Xml

About Huddled Masses

This is web site is dedicated to the musings of Joel Bennett (aka Jaykul) about technology, software, software development, the web, and the world.

Any resemblance of the views expressed and the views of my employer, my terminal, or the view out my window are purely coincidental. The resemblance between them and my own views is non-deterministic. The question of the existence of views in the absence of anyone to hold them is left as an exercise for the reader.

P.S.: I occasionally link to things I think are great. When I do, I occasionally find a "referral code" so I can make a little cash. I promise that I don't link to anything just because of that cash (I wouldn't cross the street for the amount of cash those links bring in, never mind write a whole blog post) ... but I do not promise that things I link to will stay great as time passes, nor that you will agree with me about their greatness!

Archives

  • April 2012
  • February 2012
  • January 2012
  • October 2011
  • August 2011
  • July 2011
  • June 2011
  • March 2011
  • February 2011
  • January 2011

Copyright © 2012 Joel Bennett.

Powered by WordPress and Hybrid.