Originally Posted By: ToyotaNSaturn
Apple has displaced Oracle as the company with the most security vulnerabilities
http://arstechnica.com/security/news/2010/07/apple-the-new-world-leader-in-software-insecurity.ars
Interesting...
In full disclosure, I have been a Mac user for a long time and currently own two laptops, but also have several Linux machines and a strong working relationship with Windows. I also have a decent understanding of statistics, decent enough to know that it's only used to lie to you and/or sell you something. And I have a long enough attention span to go to peruse the real data and not just the pretty graphs.
Did you read the actual report linked or just arstechnica's flamebait headline? The actual report is terrible, with only summary statistics and no real information with how things were done. This report is also very heavily focused on 3rd party applications, not on the base OS. So if you think Safari is security-flaw-prone, use Chrome or Firefox. Ditto for Quicktime, use Foobar2000 or Songbird.
Here's some 'Interesting...' tidbits from their report:
``We first examine the number of vulnerabilities of this top-50 software portfolio together with the operating system, namely Windows XP and Windows Vista. Windows 7, released in October 2009, is excluded as we have no full year of data yet.''
Translation: none of this data takes a new Windows OS into account.
``If we
extrapolate the number of vulnerabilities discovered in the 1st half of 2010 for the 2nd half we will reach in the neighborhood of 760 vulnerabilities in 2010.''
Translation: we're bad at statistics, but we can use the information we have to make alarmist predictions.
``The ranking shown in Figure 2 does not indicate the actual security (or lack thereof) in the different vendors products; it rather shows that vulnerabilities continue to be discovered in significant numbers in products from even the largest and most popular vendors including those who spend significant resources on improving the security of their products.''
Translation: Just because we jump up and down and scream about a security vulnerability doesn't mean there's actually a security flaw.
But IMO this is the most telling quote:
``Secunia is the world-leading provider of Vulnerability Intelligence and Vulnerability Management tools for enterprises and the IT-Security Industry.''
Translation: We have something to sell you if your systems aren't secure, and here's a report that tells you it isn't secure. So pay up, suckers!
Always consider the source of the information... especially when they have something to sell you.