Slashdot Log In
Microsoft or Apple - Who Is the Faster Patcher?
Posted by
Zonk
on Thu Mar 27, 2008 03:42 PM
from the go-speed-patcher-gooo dept.
from the go-speed-patcher-gooo dept.
Amy Bennett writes "And the answer is... Microsoft. Researchers from the Swiss Federal Institute of Technology analyzed 658 high-risk and medium-risk vulnerabilities affecting Microsoft products and 738 affecting Apple. They measured how many times over the past six years the two vendors were able to have a patch available on the day a vulnerability became publicly known, which they call the 0-day patch rate. What they found: 'Apple was below 20 [unpatched vulnerabilities at disclosure] consistently before 2005,' said Stefan Frei, one of the researchers involved in the study. 'Since then, they are very often above. So if you have Apple and compare it to Microsoft, the number of unpatched vulnerabilities are higher at Apple.'"
Related Stories
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.
heh (Score:5, Funny)
Re: (Score:2)
Re:heh (Score:4, Funny)
>> I've thought Bush sucked since 1999. And, since that family has their fingers in everything, it is way more on topic than say, talking about computers. I definitely wasn't cool at the time. It's like not liking Adolph in 1930 -- too soon.
Parent
Oh Boy (Score:2, Funny)
Apples to ... (Score:5, Funny)
Parent
Re: (Score:3, Informative)
Orange [microsoft.com]
Well, duh... (Score:5, Funny)
Re:Well, duh... (Score:5, Informative)
Personally as a certified Free software I'm rubbing my hands & looking forward to the Linux types who've switched for, basically, teh shiny. It's Freedom that counts folks, not features or functions or shiney... Freedom.
Parent
Re:Well, duh... (Score:5, Insightful)
Sorry, kiddo, but I'm going to have to disagree.
The "freedom" aspects are nice and everything, but without needed features or functions, you don't have jack.
Not all software has to be "free" (and not everything *should* be).
Parent
Re: (Score:3, Insightful)
True, without needed features/functions you don't have jack. But once you get needed features and functions the rest is fluff.
The thing is, though, for most people, Linux does not have the needed features. Both usability as well as aesthetics are features which Linux come up short on.
For example, I'm sure you can do any of the editing iPhoto allows on Linux using nothing but free command line utilities. In fact, I'm sure those command line utilities can actually do much more than iPhoto can. However, those utilities, however technically superior they are, are absolutely worthless to the vast majority of users.
Of course, on Linux
Re: (Score:3, Insightful)
Time to join me in the real world. People are required in order to create software. People need to be paid. Most software would be unable to make money if it is "free" as it would also end up being free as in sale price (as I have explained earlier in this thread).
Sounds like a pretty good reason to me.
To paraphrase a statement someone made on here ages ago which I happen to agree with - "Information wants to be free.
Re: (Score:3, Interesting)
If you want a reason that *only* falls on the *shouldn't* side, here's one for you -
It should be up to the person who writes it (or company who commissions it) to decide what they want to do with it. Or are you advocating that *their* freedom of choice to do with *their* creation what they want within legal bounds be taken away to give you a "freedom" that is actually a privilege granted by the peop
Re: (Score:3, Funny)
AIs are posting on slashdot!? better than nuking us I s'pose...
If a tree falls ... (Score:3, Funny)
what day of the week is it? (Score:5, Funny)
Look at it my way (Score:2, Insightful)
What affects me, is the severity of these bugs that need to be fixed. If that is analysed, I'm sure that Apple prioritises it's bugs better, and fixes the more important bugs earlier and more efficiently than Microsoft. Moreover, the bugs at Microsoft would be more severe, and a lot of patches are released in a hurry without testing properly. A perfe
Re:Look at it my way (Score:4, Insightful)
From your post: "What affects [sic?] me, is the severity of these bugs that need to be fixed. If that is analysed, I'm sure that Apple prioritises it's bugs better, and fixes the more important bugs earlier and more efficiently than Microsoft."
You're sure, huh? Hmmmmm...I'm not sure if you're an Apple fanboi or a Microsoft hater, but either way, you can never be sure about anything (except death and taxes). So, as soon as you said that line, everything else you said became a non-argument, argument.
Parent
Re:Look at it my way (Score:4, Insightful)
Parent
Re: (Score:3, Insightful)
I was going to mention how many of Microsoft's patches have induced later zero-day bugs but more or less, you beat me to that point.
I also wanted to mention though how much more frequently Microsoft vulnerabilities are taken advantage of. I know this is simply a metric of Microsoft's percent market share with the likelihood of a computer running a Microsoft product, and not with the programming ability level at Microsoft, but it still means that if left unpatched for a fraction of th
Re:Look at it my way (Score:4, Insightful)
One of the major features of Windows, and one of the most powerful, is that it is widely adopted and incumbent for the majority of the market. This provides them with the network effect that increases the value of this OS. It's only fair that the same penalty that is partnered with this popularity is taken into consideration when comparing operating systems.
Parent
Re:Look at it my way (Score:4, Insightful)
If there was a car that had a critical flaw and exploded into flames if you hit it from behind hard enough.... BUT only 0.03% of Americans drove the car... then the NHTSA shouldn't really consider that a 'critical' flaw, it shouldn't be viewed as 'badly' as the same type of flaw in a Honda Accord (driven by far more people)...
All because the market share of this explosion-prone car is low?
That's some whacked-out thinking right there. Just because the company can't get market share doesn't lessen the potential (or real) impact of the vulnerability. I don't care if that's Apple or Nortel or Mythic Entertainment.
Parent
Re: (Score:3, Interesting)
More like there are two types of locks for your front door, we'll assign these locks random brands: Capple and Spikrosoft. Capple has a very small percentage of the market and Spikrosoft has a very large percentage.
Let's say there is a vulnerability that will allow access, but you need to order a specific sets of tools to gain access to each individual brand of lock. Because Spikrosoft has a much larger market share, the tools specific to breaking into that lock will much more heavil
Of course! (Score:5, Funny)
Apple's shortcomings (Score:5, Interesting)
If they really want to be taken more seriously in the enterprise market, they're going to have to step up and treat these things a bit more professionally, instead of just basically saying "trust us and don't ask too many questions".
Re:Apple's shortcomings (Score:5, Informative)
It's specific enough for me, listing every application / library, impact, and description.
Parent
Re: (Score:2)
Re:Apple's shortcomings (Score:4, Insightful)
As for software, they use plenty of open source and contribute back to the community. What they don't want outside involvement with is their core hardware.
Parent
Re:Apple's shortcomings (Score:5, Insightful)
No, Apple does not want outside involvement in their products, and has not been friendly to the open source projects it draws on for some of its products. If by "give back to the community," you meant, "begrudgingly provide some code to the Konqueror team but never really get it right with OpenDarwin," I guess you would be right. They actively work against third party software syncing with the iPod, and have overly restrictive terms for developing software for the iPhone.
Apple only accepted interoperability and broad third party software because it was on the verge of bankruptcy, not because it is a company that sits on a moral high ground. Apple's strategy, originally, was to keep themselves completely separate, so that buying one Apple computer required you to change your whole infrastructure. This was and remains a failing strategy, and so they modified it so that just enough third party development was possible to keep their systems relevant, but nothing more. iPods only support those formats that Apple chooses (and many iPods cannot be reflashed, because they were designed to only be capable of running Apple's software). iPhones only support some third party development, and developers are required not to step too far from where Apple wants them to be. I cannot build a computer that runs Mac OS X on my own, and it is not likely that Apple will ever allow for this. Like I said, you can construct any number of reasons for these things, but there is no denying that Apple does not want third parties developing software for Apple's platforms.
Parent
Re:Apple's shortcomings (Score:5, Insightful)
You're also combining the lack of customizable hardware with a lack of customizable software. What they want to retain control of is the hardware and the software platforms. 3rd parties can easily build on top of that. The intent is to manage the user experience. Otherwise they feel users will end up with a mess, like on the Windows platform.
Parent
Article Lacks Important Information (Score:5, Insightful)
Until I see an article that doesn't throw out one number and then fill the rest of the page with useless fluff and speculation, I'm putting my money on Apple.
yes, and if grandma had wheels..... (Score:3, Funny)
One can always play with the criteria to get any desired winner.
Going by raw number of anything you lose any distinctions as to the severity or impact of each problem.
In general a buffer-overflow in the Windows kernel is a heck of a lot more dangerous than a similar problem in OSX can ever be.
Re:yes, and if grandma had wheels..... (Score:5, Insightful)
Parent
Re: (Score:3, Insightful)
On the front page of
The person took complete control of the mac box by having the user click on a link in safari.
The rules of this contest state that only non-published attacks can be used. This guy just happened to have this one sitting around to use.
How is this a valid test? (Score:5, Insightful)
quick! patch it! FASTER! QUICK! (Score:5, Insightful)
I've seen programmers churn out patches really, really fast, and create 3 new bugs for every one they "fix".
Don't encourage them.
meh (Score:4, Informative)
Where's the Beef? (Score:4, Informative)
So this is an article that doesn't give any answers to the question it poses and references a study presented at blackhat, but which has not yet been published and in fact whose presentation is not even online yet.
Can't we at least wait until we have some sort of data to discuss before embarking on half-assed arguments about how relevant the data is and if the methodology is credible?
Here's a link to the original research paper (Score:4, Informative)
That link is to a browser view of the PDF at pdfmenot.com which caches the actual PDF, so the poor researcher's personal web site doesn't get hit too hard. You could download the original PDF from there if you really want to.
Thats because M$ just has more 'features' (Score:5, Insightful)
Re: (Score:3, Informative)
Exactly. MS intentionally sits on vulnerabilities and doesn't announce them publicly until the patch is available. Apple, on the other hand, uses a lot of free and open-source software where full disclosure is considered important enough to notify all users through normal mailing lists, newsgroups, and other channels.
This study is intentionally biased to make MS look good and Apple look bad. Wh
Re: (Score:3, Informative)
> 658 [...] affecting Microsoft products and 738 affecting Apple
Re:Just more FUD (Score:5, Interesting)
The study speaks of things that can be known. Your response speaks of things that can't be known. You seem to be slinging the uncertainty and doubt part yourself.
Parent
Re: (Score:2)
Re:Just more FUD (Score:5, Funny)
On your second point, uncertainty & doubt, I don't know what to think as once we know what needs to be known these will disappear.
What was the study about again?
Parent
Re: (Score:2, Insightful)
Re: (Score:3, Interesting)
Now that Apple has nontrivial market share...
While Apple is growing rapidly, market share is still trivial overall.
"Apple did not rank in Gartner's top 5 worldwide PC vendors, No. 5 of which was Toshiba with a 4.4 percent share."
http://www.appleinsider.com/articles/07/10/17/apples_u_s_mac_market_share_rises_to_8_1_percent_in_q3.html [appleinsider.com]
Re: (Score:3, Insightful)
I was actually responding to the assertion that Apple's market share is no longer trivial, and provided some evidence to su
Re:Just more FUD (Score:5, Insightful)
It's early days still in Apple's second-coming. There's no denying that their market share will only increase for the next few years. There's also no denying that at the moment their installed base is still trivial. Mind share for people making exploits will also take time to get to the same level on the Mac as what it is for PCs.
This is fairly obvious stuff -- history has shown that no software developer takes security seriously unless they have absolutely no option. MS crossed that threshold a long time ago and really got their shit together. Apple hasn't reached the threshold yet, but all indications are that its just a matter of time. There's a world of AJAX apps out there waiting for their trial by fire too..
Parent
Re:Just more FUD (Score:5, Interesting)
Parent
A few OS X and iApp bugs and crashes.. (Score:3, Interesting)
Name the applications, version of the OS and the hardware you're using.
First a few annoying bugs Apple has taken way to long to fix:
OS X 10.5.2, Mail.app, when accessing some IMAP4 accounts the "Get Mail" button fails to retrieve mail for some accounts. It's a know issue and it has been since the 10.5.2 update. I am not the only one to run into it, I checked the Apple forums and tested Mail from several different networks and two different Macs. I 'fixed' this bug in Mail.app by switching to Thunderbird.
OS X 10.5.2, When printing to a printer connected to an Airport Express