Linux Is the Least Secure System
2002:11:28 ·Source: Nikkei BP
Microsoft should be happy. According to a report published by the Aberdeen Group, the least secure OS is not Windows, but Linux. The report points out that in the 10 months since the start of this year, more than half of the security warning notices, "Security Advisories," issued by the U.S. security organization CERT were related to Linux and open-source solutions. This conclusion is bound to change the view that independently developed software such as Windows is worse than open source in terms of security. In addition, another part of the report points out that as for independently developed UNIX, the number of reports during the same period was about the same as Linux. So among the current mainstream OSes, is Windows the safest OS?
The report points out that "the vast majority of Linux, UNIX, network devices, and source-available software have become a major reason security vulnerabilities continue spreading to IT buyers. Of the 29 Security Advisories reports obtained in the first 10 months of 2002, 16—in other words, one out of every two—were related to open source and Linux. During the same period, there were 7 vulnerability reports related to Microsoft products, accounting for about one quarter."
This highly shocking report runs completely contrary in many respects to the common understanding widely accepted by society. Specifically, "first, the peak period of 'Trojan horse' attacks targeting Windows was in 2001, when CERT reported 6 cases; however, since the beginning of this year they have completely disappeared, not even one. But Trojan horse attacks aimed at Linux, UNIX, and open source doubled in 2002 compared with 2001. This shows that, contrary to media reports, Linux and UNIX are more vulnerable to Trojan horse attacks than other OSes, and the UNIX-based Mac OS X has the same vulnerability. The most serious problem lies in open-source software used in Internet-connected devices such as routers, Web servers, and firewalls. It can be said that the state of using these devices and software products has already become an 'unfortunate accomplice' that lets intruders seize control."
In addition, the report also points out that "with regard to six kinds of vulnerabilities, the open-source camp has always emphasized that compared with vendors developing their own proprietary products, open source is rapidly improving and therefore is less affected. Hardware and software using open source must undergo extremely strict security testing before product shipment. An especially serious problem in the vast majority of Linux distribution packages is the lack of automatic update technology like that provided by recent Windows."
It is actually very easy to criticize Microsoft in terms of security measures. But what cannot be denied is that compared with competing products, the overwhelming majority of users and systems are using Microsoft software. Before Linux is used by as many users and systems as Windows, it may be very difficult for Linux to achieve the same level of security as Windows. At least today, when its degree of adoption is still far below that of Windows, reports of damage involving Linux will continue to increase.
2002:11:28 ·Source: Nikkei BP
Microsoft should be happy. According to a report published by the Aberdeen Group, the least secure OS is not Windows, but Linux. The report points out that in the 10 months since the start of this year, more than half of the security warning notices, "Security Advisories," issued by the U.S. security organization CERT were related to Linux and open-source solutions. This conclusion is bound to change the view that independently developed software such as Windows is worse than open source in terms of security. In addition, another part of the report points out that as for independently developed UNIX, the number of reports during the same period was about the same as Linux. So among the current mainstream OSes, is Windows the safest OS?
The report points out that "the vast majority of Linux, UNIX, network devices, and source-available software have become a major reason security vulnerabilities continue spreading to IT buyers. Of the 29 Security Advisories reports obtained in the first 10 months of 2002, 16—in other words, one out of every two—were related to open source and Linux. During the same period, there were 7 vulnerability reports related to Microsoft products, accounting for about one quarter."
This highly shocking report runs completely contrary in many respects to the common understanding widely accepted by society. Specifically, "first, the peak period of 'Trojan horse' attacks targeting Windows was in 2001, when CERT reported 6 cases; however, since the beginning of this year they have completely disappeared, not even one. But Trojan horse attacks aimed at Linux, UNIX, and open source doubled in 2002 compared with 2001. This shows that, contrary to media reports, Linux and UNIX are more vulnerable to Trojan horse attacks than other OSes, and the UNIX-based Mac OS X has the same vulnerability. The most serious problem lies in open-source software used in Internet-connected devices such as routers, Web servers, and firewalls. It can be said that the state of using these devices and software products has already become an 'unfortunate accomplice' that lets intruders seize control."
In addition, the report also points out that "with regard to six kinds of vulnerabilities, the open-source camp has always emphasized that compared with vendors developing their own proprietary products, open source is rapidly improving and therefore is less affected. Hardware and software using open source must undergo extremely strict security testing before product shipment. An especially serious problem in the vast majority of Linux distribution packages is the lack of automatic update technology like that provided by recent Windows."
It is actually very easy to criticize Microsoft in terms of security measures. But what cannot be denied is that compared with competing products, the overwhelming majority of users and systems are using Microsoft software. Before Linux is used by as many users and systems as Windows, it may be very difficult for Linux to achieve the same level of security as Windows. At least today, when its degree of adoption is still far below that of Windows, reports of damage involving Linux will continue to increase.
我完全同意设想建立DOS组织“DOS联盟” ,也就是说和Wengier、以及“起步”站长莫老师等DOS战友一起来建立这个“DOS联盟”,以发展我国自主OS(操作系统)的高度去完成我们共同的愿望。
------党委书记
------党委书记







target.

