LWN.net Logo

Simplistic solution?

Simplistic solution?

Posted Jul 16, 2008 22:27 UTC (Wed) by bojan (subscriber, #14302)
Parent article: Handling kernel security problems

> It has been argued at times that all bugs have security relevance

I guess stable folks could adopt a cynical view here and just open a CVE for every new
release, claiming that unknown security issues _may_ have been fixed, given that _bugs_ have
been fixed. Then everybody would be happy :-)


(Log in to post comments)

Simplistic solution?

Posted Jul 16, 2008 22:57 UTC (Wed) by nix (subscriber, #2304) [Link]

Microsoft especially. They love counting these things and saying 'oh, look 
how insecure Linux is!'

Simplistic solution?

Posted Jul 16, 2008 23:01 UTC (Wed) by pr1268 (subscriber, #24648) [Link]

Oh, the FUDsters at <Software company in Redmond> would love that! Just picture it:

Report of Operating System Security Vulnerabilities, January-December <year>

  • <Software company in Redmond> <Glass panes in wall>: 8†
  • Linux: 69‡

† A random, arbitrary number I just made up.
‡ Based on number of kernel releases in 2007 (by looking at timestamps of the Changelogs listed). May be somewhat inaccurate. Doesn't even consider multiple bugs fixed in each release.

Simplistic solution?

Posted Jul 17, 2008 0:29 UTC (Thu) by bojan (subscriber, #14302) [Link]

If you look at those statistics now, Windows is already way ahead of Linux OSes in terms of
security:

http://blogs.technet.com/security/archive/2007/03/21/wind...
http://blogs.technet.com/security/archive/2008/05/15/q1-2...

So, nothing lost, I guess...

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds