• On ZDNet: Why I Will never buy a Mac
November 26, 2007 4:23 PM PST

Microsoft FUDwatch: Windows vs. Linux security

by Matt Asay

It's been at least a week since the last bout of Microsoft FUD hit the wires, so I guess it was time for a new wave. Today's FUD comes from an article Microsoft released on how its security compares with that of Linux. It should come as no surprise that Windows comes off as the Second Coming while Linux is left on the wrong side of Acheron.

It's amusing to watch Microsoft attempt to claim the moral high ground with security. Pat Edmonds, Senior Product Manager for Microsoft, writes that the "many eyes makes all bugs shallow" aspect of open source doesn't work for security, and points to several studies that purportedly confirm that Windows is more secure than Linux:

In reality, the "many eyes" mantra for Linux security has largely been disproved for two primary reasons. First, it assumes that all of the "eyes" are qualified to know what they are looking for. In reality, security expertise is not widely distributed across most users, but is actually a fairly rare and valued skill set. [Mr. Edmonds should know, as this skillset has been sorely lacking at Microsoft for decades.]

Second, the "many eyes" argument implies that all the "eyes" want to voluntarily peruse code for bugs. Actually, debugging and testing code is not necessarily one of the more exciting pastimes for many volunteer developers, who more often than not would rather devote their spare time to creating the next great application. As a result, it is not surprising that Ben Laurie, Director of Security at the Apache Foundation, stated, that "although it's still often used as an argument, it seems quite clear to me that the 'many eyes' argument, when applied to security, is not true."...

Microsoft is adept at twisting the truth about how open source works. Every person in that company knows or should know by now that significant commercial interests are involved in open-source development, and especially Linux. So when Mr. Edmonds refers to "volunteer developers," he's surely creating a false strawman (just as Bill Hilf recently did).

Not content with this minor indiscretion, Mr. Edmonds quotes Ben Laurie and tries to use his words against him, to which Mr. Laurie replies:

...[F]ocusing on the "many eyes" fallacy fails to capture an important difference between open and closed source: namely that if I want to do a security review of an open source product, I can. For Microsoft's products I would have to (potentially illegally) reverse engineer them before I could even start.

Secondly, the fact that more bugs are found in an open source product than a closed source one is not, in itself, an indicator that more bugs exist - or even are known. It is equally plausible that the availability of the source encourages a more collaborative approach to security, so that those few who do search for bugs are more inclined to report them than to exploit them. It is also the case that, since open source products cannot conceal their security fixes, they are more inclined to make them public, even if they had no need to....

Thirdly, the study on which they rest their conclusion is comparing apples and oranges. From the report

For each operating system, Secunia tracks all vulnerabilities that affect a full installation of all components and packages included in the current release.

A full release of Windows is far less functional than a full release of Red Hat. Windows will only include the base operating system, whereas RH will include pretty much every open source project you've ever heard of. So, simply counting vulnerabilities in a full install is highly biased. A fairer comparison would be to look at an install of RH with equivalent functionality. Presumably that doesn?t cast Windows in such a favourable light, or they would have done it.

Finally, their study shows that Windows actually had more bugs classified as "highly critical" than RH. 5 for Windows versus 2 for RHES 4 and 1 for RHES 3. I would say this makes the conclusion of even this biased study more than a little suspect.

Boiled down, Microsoft is effectively saying, "Trust us to help you be secure" and open source responds, "Trust us, but also trust yourself." Open source doesn't force its adopters to give up security to the hands of a vendor, though there are certainly open-source vendors who are happy to enhance security and stand behind it for a fee.

Microsoft, for its part, clearly views itself as an island: a fortress that can take care of all its customer needs, including interoperability:

Interoperability by design is a key element that is enabled through the Microsoft development model. By taking into account the interoperability needs of Microsoft?s broad customer base, which includes the need to exchange data with software and hardware from more than 100,000 other companies, during the design phase Microsoft can implement appropriate standards and leverage relationships with other vendors to ease the burden on customers who need to integrate Microsoft products with software from other vendors including open source.

Microsoft's model is, "Trust us to take care of everything. We're a nearly omnipotent gatekeeper." In some ways, this is true. Microsoft has a lot of engineers and a lot of experience with interoperability.

But consider the open-source alternative: while vendors like Red Hat, Canonical, and Novell will take care of the most important interoperability points, the community is able to add on its own such that there is no single point of failure. For example, internationalization of products tends to happen much, much faster in open source than in proprietary products. Why? Because you're not waiting for those 10 smart developers within Microsoft tasked with internationalization to get to your preferred language, which might be German or it might be Swahili.

Also, as I read through Mr. Edmonds article, I got the sense that the basic model is always "Trust us to bake security into the product." But this overlooks the biggest problem: no system is necessarily perfectly secure from the start, so what happens after the code release is often as important, if not more so, than what happens before.

With a proprietary product you entrust all security to the vendor. That may work most of the time. But for those times when it doesn't...well, you're worse than on your own. You're on your own without the legal right to help yourself. That doesn't sound like much of a security proposition to me.


Via Slashdot's Firehose.

Matt Asay brings a decade of in-the-trenches open-source business and legal experience to The Open Road, with an emphasis on emerging open-source business strategies and opportunities. Matt is vice president of business development at Alfresco, a company that develops open-source software for content management. He is a member of the CNET Blog Network and is not an employee of CNET. Disclosure.
Recent posts from The Open Road
What soccer team would your company be?
Open-source licensing: Your mileage may vary
Open source to shape cloud computing, but not dominate it
Off-topic: Why can't I have this job?
Legalized drugs, now open source. Those crazy Dutch!
Will 'good enough' virtualization topple VMware?
Linux community codes around Microsoft's FAT patents
As Mozilla 'upgrades the Web,' Microsoft must upgrade its pace
Add a Comment (Log in or register) (6 Comments)
  • prev
  • 1
  • next
MS couldn't emulte open source process
by mrashley November 25, 2007 10:46 PM PST
Good post, Matt.

Even if Microsoft wanted to, they couldn't create the same community and ecosystem around their operating system like Linux has.

Read my post if you'd like to read more. http://www.networkworld.com/community/node/22229

Thanks
Mitchell
Personal blog: http://theconvergingnetwork.com
Reply to this comment
He's right about many eyes
by rpmyers1 November 26, 2007 10:23 AM PST
Many eyes is no guarantee. How long was the exploitable double free in zlib? How long was the hard coded password in Phoenix?

Of course, they were eventually found and fixed. The potential for many eyes still outweighs anything that the closed source world offers (Remember Oracle's "Unbreakable"?)
Reply to this comment
Based on incorrect data
by iamamoose November 26, 2007 2:31 PM PST
The metrics used in the studies are based on third party severity ratings which were shown to be inaccurate for Red Hat vulnerabilities. See:
http://www.awe.com/mark/blog/200708281105.html
Reply to this comment
Microsoft is more credible than you
by menotbug November 27, 2007 8:26 AM PST
We all know Microsoft markets, and probably stretches the truth, but doesn't everyone? With yesterday's digging of
http://www.digg.com/apple/CNet_rates_Vista_one_of_worst_products_in_history

I have absolutely not respect for Cnet, diggers will agree.
Reply to this comment
by Dango517 November 28, 2007 8:38 PM PST
A reliable security benchmark is needed that is measurable and consistent across all platforms. Any volunteers? How about you McAfee or you Norton? What about you Computer Associates or Kaspersky?
Reply to this comment
by Dango517 November 28, 2007 9:19 PM PST
Here is some additional information from June 21st 2007:

http://blogs.csoonline.com/windows_vista_6_month_vulnerability_report
(6 Comments)
  • prev
  • 1
  • next
advertisement

Making sense of Windows 7 upgrades

faq The basics and the fine print on Microsoft's options for those eyeing the next operating system from Redmond.
• Full Windows 7 coverage

Road Trip 2009: Big Sky Country

CNET News reporter Daniel Terdiman takes his car full of gadgets to the Rockies and the Great Plains in search of tech, science, nature, and more.
• America's Fortress: Cheyenne Mountain

About The Open Road

Matt Asay brings a decade of in-the-trenches open-source business and legal experience to the Open Road, with an emphasis on emerging open-source business strategies and opportunities. Matt is general manager of the Americas division and vice president of business development at Alfresco, a company that develops open-source software for content management. He is a member of the CNET Blog Network and is not an employee of CNET. Disclosure.

Add this feed to your online news reader

The Open Road topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right