|
|
Log in / Subscribe / Register

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 0:19 UTC (Thu) by FLHerne (guest, #105373)
In reply to: I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic by PaXTeam
Parent article: Dutch consumer group sues Samsung over Android updates (OSNews)

If the maintainers didn't fix a bug because they didn't find it for a few years, that doesn't say much about their general attitude to security. They might have crap code and no testing, or it might have been some really obscure edge-case in an otherwise good project.

On the other hand, if a serious vulnerability is left unpatched for more than a few days _after_ the maintainers are told, you know _for sure_ not to rely on them for security. No excuse for leaving a hole when you know it's there.

---

Also, bugs exploited by widespread malware get reported fairly quickly by reverse-engineering the malware. So the number of publically-known bugs should track the number known to typical malware authors with a few weeks/months' delay.
That's not true for targeted, inconspicuous malware as deployed by governments, but few users complain about that.


to post comments

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 1:16 UTC (Thu) by PaXTeam (guest, #24616) [Link] (2 responses)

> They might have crap code and no testing, or it might have been some really obscure edge-case in an otherwise good project.

that distinction would say very much about that attitude to security. however i don't see how the suggested metric helps here.

> if a serious vulnerability is left unpatched for more than a few days _after_ the maintainers are told, you know _for sure_ not to rely on them for security.

except for certain individuals or teams with single-digit member counts no entity can turn fixes out that fast so it's still not a useful metric because it would make most entities unreliable. and i still don't see how a phone becomes secure on those days when the public is unaware of any particular vulnerability.

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 11:42 UTC (Thu) by jospoortvliet (guest, #33164) [Link] (1 responses)

As was pointed out, the metric is not meant to make phones more secure. Just to show how quickly vendors react to known security issues - one aspect of security, among many. I think it is a great idea.

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 11:50 UTC (Thu) by PaXTeam (guest, #24616) [Link]

compare your

> As was pointed out, the metric is not meant to make phones more secure.

with Wol's

> If X is greater than Y, then your phone is secure at least some of the time.

clearly there's disagreement already on what this metric is supposed to mean.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds