Microsoft issues Vista security scorecard, gives itself an A-plus
Vista has a third of the bugs of XP, a fifth as many as Mac OS X, company says
Computerworld - A Microsoft Corp. executive yesterday said Windows Vista's first 90 days was a huge security success when compared with the opening three months of Windows XP, the current Apple Inc. Mac OS X and three flavors of Linux.
Jeff Jones, the strategy director in Microsoft's security technology unit, tallied up vulnerabilities patched during the first 90 days of Vista, XP, Mac OS X 10.4, Red Hat Enterprise Linux 4 Workstation, Ubuntu 6.06 LTS, and Novell SuSE Linux Enterprise Desktop 10.
He gave Vista the checkered flag.
"Vista has an improved security vulnerability profile over its predecessor, and a significantly better profile relative to comparable modern competitive operating systems," Jones asserted in his blog. By his count, Vista has been hit by just one vulnerability since its introduction to enterprises at the end of November. The bug, which was in the antimalware scanning engine used by the bundled-with-Vista Windows Defender, was patched last month.
By comparison, said Jones, in their first 90 days, Windows XP was nailed with 14 bugs, Mac OS X 10.4 (Tiger) with 20, Red Hat with 137, Ubuntu with 71 and SuSE with 80.
Even when vulnerabilities that were disclosed but not patched are added in, Vista still comes out far ahead. Its five total bugs -- one patched, four made public but not fixed as of Feb. 28 -- compared favorably with XP's total of 18, Mac OS X's 27, Red Hat's 201, Ubuntu's 100 and SuSE's 111.
"As an early and tentative indicator, this is good news for Windows Vista security," said Jones in a report he issued of his findings (download PDF).
But simply counting up vulnerabilities, patched or not, doesn't tell the whole story, argued Oliver Friedrichs, senior director of Symantec Corp.'s security response team.
"The severity of [a] vulnerability plays into this, too," Friedrichs said today. "A single vulnerability that has a high severity could lead to the next Sasser or Blaster [worm], but an OS with a larger [bug] count, but with [ones rated] less high may be in a better defensive position overall."
Likewise, Friedrichs said, comparing Windows with any other operating system is always dicey because of the overwhelming market share Microsoft's products enjoy. That means flaws in Windows are much more likely to be exploited by attackers.
"A high-severity vulnerability may not receive widespread exploitation on another OS," Friedrichs said. "That's not uncommon. It doesn't diminish the criticality of the vulnerability itself, of course. For that vendor's customer base it does present a serious risk, but the overall risk to the Internet may not be much."
Friedrichs also questioned whether 90 days of Vista was an apples-to-apples comparison with XP or other operating systems, what with Vista's two-stage roll-out. "This [scorecard] started the day it shipped to enterprises, but they have a much much slower [Vista] adoption rate than consumers. The fact is, the installed base of Vista has not grown as quickly as did XP's in its first 90 days."



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- VMware View Optimization Guide for Windows 7
- This document provides guidelines for configuring a standard Windows 7 image to be used within a VMware View™ environment, providing administrators with the...
- Watson - A System Designed for Answers. The future of workload optimized systems design
- Watson is a workload optimized system designed for complex analytics, made possible by integrating massively parallel POWER7 processors and DeepQA technology. Read the...
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring... All Operating Systems White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®... All Operating Systems Webcasts