Apple Mac less secure than Windows in 2007?

Apple Online Store“During 2007, Apple has patched more than ten times the number of critical vulnerabilities in Mac OS X compared to the number patched in Microsoft Windows,” Tom Espiner reports for ZDNet UK. “George Ou, a writer for ZDNet Australia sister site ZDNet.com, analysed in-depth statistics from security research company Secunia as a basis for his research.”

MacDailyNews Take: ROTFLOFAO, he called what Ou does “research!” Please see related articles:
• ZDNet’s George Ou Exposed as Ignorant Microsoft Shill – RoughlyDrafted
George Ou’s Greatest Apple Hits! – The Macalope
George Ou: When Gerbilling isn’t fun enough – Artie MacStrawman’s Apple Orchard
George Ou’s Bad Idea: Comparing Apple Ads to Nazi Propaganda – Wired

Espiner continues, “He found that Apple’s latest operating system, Mac OS X, faced more critical flaws than Windows XP and Vista combined… Ou made the comparison as an indicator of how many vulnerabilities might exist in 2008, rather than a comparison of the relative security of the operating systems.”

“Some experts have said that counting vulnerabilities is not necessarily reliable as a measure of security,” Espiner reports. “Tristan Nitot, president of Mozilla Europe, told ZDNet.co.uk this month that it was more important to take into account the time it takes to patch vulnerabilities.”

Espiner reports, “The amount of exploit code available in the wild also has an impact on security. While there are thousands of pieces of code that seek to exploit Windows XP vulnerabilities, exploit code for Mac OS X is relatively rare.”

Full article here.

MacDailyNews Take: In “honor” of George Ou, we’re going to continue surfing the Internet unimpeded with our Mac OS X Firewall turned off for another six years.

78 Comments

  1. Another conspiracy attempt / FUD from the M$ proxies ie: ZNET.

    A key gauge would be what actual vulnerabilities are out in the wild and being exploited.

    I have a feeling the actual OSX vulnerabilities being exploited is no where close to the quantity for XP and/or Vista.

  2. I was beginning to worry that all these reports of security issues might be true.

    I too will ignore them all along with the false alarms that Apple itself sends out in the form of some ‘security updates’ to the OS and various Apple apps.

    Man, do I love the Mac!

  3. I guess Ou’s point is that he would rather have an operating system from a company which doesn’t acknowledge or correct errors rather than a company which does updates and corrections?

    I think it’s rather amusing that people expect software to be perfect the first time it’s written, every time a new feature is added, etc. Software is written by people, and people are aberrated and make mistakes. Plus, a company cannot possibly test for every possible combination of software, hardware and user interaction. Thus, Apple corrects mistakes, etc. by issuing patches. And far before ANY malicious attack can be made.

    It’s pretty remarkable how fast Apple had OS 10.5.1 prepared and released.

    At least Apple doesn’t bury its head in the software sand and pretend the problem doesn’t exist.

  4. Vulnerability does not equal exploit. All exploits are not equal. Macs don’t get turned into hackers’ spambots. If there are so many security issues with Mac OS X, where are all the exploits? Oh, there aren’t any, just Trojan Horse malware for the gullible and “proof of concept” stuff in the labs of security companies. Never mind…

    Apple should be applauded for diligently fixing potential issues in a timely manner. The reason there have not been any meaningful exploits is because hackers can’t do anything meaningful (worth their time and effort) with these so-called “critical vulnerabilities.” The low-hanging fruit will always be Windows.

  5. It’s great that they come out with the updates as often as they do, but I still do a backup before I install. I usually just wait till the weekend since I do my weekly Super Duper backup then. You never know when one of these things can cause problems. Better safe than sorry.

  6. When will these idiots learn that vulnerabilities are not exploits?

    A vulnerability is a potential problem. When someone takes advantage of a vulnerability, then it becomes an exploit.

    I sometimes leave my house unlocked when I go out. That’s a vulnerability. I have two German Shepherd Dogs inside the house. there have never been any exploits.

  7. The difference between Apple and Microsoft here is, Apple actually fix majority of the holes before someone exploits them, and Microsoft waits until 50% of windows user have some sort of virus. Even then they still leave it up to the anti-virus programs.

  8. Comparing security by counting vulnerabilities, but ignoring actual exploits makes as much sense as comparing smart phones by counting features, but ignoring whether people can satisfactorily use those features in the real world.

  9. Amazing, new Mac user here, you all make up explainations to justify your beliefs that Apple can do no wrong.

    sounds like religion, is this a cult thing?

    example:
    A key gauge would be what actual vulnerabilities are out in the wild and being exploited.

    why does this matter, I hack, I tell no one my exploits don’t make virus either to have get out of control.

    give me your ip address, I;ll get in your machine

    SSH is open by default on Mac’s, people make up easy to guess passwords. simple dictionary attack I pwned you.

  10. “In “honor” of George Ou, we’re going to continue surfing the Internet unimpeded with our Mac OS X Firewall turned off for another six years.”

    LOL… excellent. Lets email Ou that we’re all going to do this.

  11. Idiots,

    Microsoft pays security companies to look for and publicize security holes in Mac OS X so the vulnerability patch count of Mac OS X vs Vista makes Vista somehow look better.

    The truth is, with what few security holes there were in OS X already patched, OS X is very secure.

    Vista, on the other hand, is full of secret, legacy code that is full of undiscovered vulnerabilities just waiting to be found and exploited.

    Let’s compare exploits or unpatched, unfound vulnerabilities. There’s no way Vista wins that game.

  12. ya know, it’s funny. i go to hardocp.com quite a bit, and they reported on this too – of course, they didn’t actually think about it when they posted it, they just said something like “so much for most secure OS in the world!” – they have a lot of information and news that i enjoy reading but their anti-apple bias actually manages to be more irritating than the anti-MS bias here – mostly because at least the anti-MS stuff here has some basis in REALITY, instead of just in theory. MDN’s take is awesome, and i’ll be joining them in not worrying about my built-in firewall (four years of OS X for me and not one security/virus/malware issue the whole time).
    as for hardocp: they can stfu and enjoy running ad-aware and spybot and AVG while i actually get some web surfing done!

  13. >>we’re going to continue surfing the Internet unimpeded with our Mac OS X Firewall turned off for another six years.<<

    Not me. I’m having my firewall turned on. Also on my servers both Ubuntu Linux and FreeBSD the firewalls are always on….. Also my router has a built in firewall which is….. yes you guessed it: always on

    Having a firewall and not using it is plain stupid….

  14. I’m game… you proclaim:

    “SSH is open by default on Mac’s, people make up easy to guess passwords. simple dictionary attack I pwned you.”

    Do your stuff, get into my machine, impress me

    ” width=”19″ height=”19″ alt=”grin” style=”border:0;” />

  15. “Do you also want the keys to my house and car? Neither has an alarm system.”

    No, just leave the doors unlocked for us, because that’s the equivalent of going on the Internet without a firewall and anti-malware protection.

    I know, in sleepy little MacTown where you live you don’t get much crime, so the population feels safe and secure for now with the doors wide open, no alarm systems and the locks not working even if you did choose to close the doors.

  16. we’re going to continue surfing the Internet unimpeded with our Mac OS X Firewall turned off for another six years.

    Do you also drive without seat belts because your car has a great safety rating?

    Some risks aren’t worth taking.

  17. I don’t get the mentality of people that could have enjoyed the last 20+ years of relatively virus free existence with Apple’s Macintosh but consciously chose not to and continue to do so.

    Instead they insist on crying “the sky is falling” if there is a possible virus threat on the Mac. Meanwhile, they have had to put up with over 100,000 virus’ on a Microsoft Windows PC – the endless supply of Windows malware And pathetic Anti-virus support that Microsoft has sold them. – I mean, Microsoft actually sold it instead of just including it as part of the OS. That in itself is worthy of a “WOW”. How pathetic is that of Microsoft? Very!

    Still, the Mac in comparison to the PC is completely virus free. Why wouldn’t you want to be a part of that? I certainly enjoy that aspect of the Mac.

    The Mac has a Long Long way to go to catch up to Windows in the virus world – and so far Windows has maintained a very “unhealthy lead”. A lead Microsoft doesn’t appear to be able to relinquish.

    Security through obscurity? – Whatever – that’s perfectly fine with me whether it’s true or not. It’s more secure. I’ll take it. You would be a fool not to.

  18. Apple CHOOSES to stay on top of things

    RATHER then be moved over by hacking hell raisers PAID by MacroSloth and it’s team of Anti-virus sellers.

    See Apple care about it’s status and will continue.
    MacroSloth sits and basks it’s glory dreaming up useless plots to invade Apple.

    They laugh in fear knowing soon their time will end shortly.

    THEY are insecure over there at Macrosloth stink.

    jay and my pointed plunger

  19. All this back and forth mud-slinging is actually part of Steve’s evil plan for global domination.

    He is siccing the journalists and the die-hard fans on each other. Once the swirling vortex of cynical-obsessive deconstructionism vs. rabid loyalty reaches critical mass, the two will react and go supernova, destroying both groups and clearing the way for total world control.

    Trust me

  20. my machine is on for your musing

    lets play ball dick.

    WHILE your attempting… remind yourself that I will be pulling your IP with custom tracing software that I personally wrote…

    I will OWN U… Archibald !

    LET PLAY

  21. “Amazing, new Mac user here, you all make up explainations to justify your beliefs that Apple can do no wrong.

    sounds like religion, is this a cult thing?

    example:
    A key gauge would be what actual vulnerabilities are out in the wild and being exploited.

    why does this matter,”

    are you really that stupid? you have to have that explained to you?

  22. The main reason for the mac having more known vulnerabilities is the fact that most components of OSX are open source. So the code can be audited by anyone. Therefore windows could have more vulnerabilities then osx as their code is not accessble by anyone but Microsoft. As Microsoft has been known to patch vulnerabilities secretly i wouldn’t be surprised if there is more.

  23. “Security through obscurity? – Whatever – that’s perfectly fine with me whether it’s true or not. It’s more secure.”

    Security through obscurity is regarded by any security professional as no security at all.

    Say all you like that it’s good that Apple has had 10 times the vulnerabilities of Microsoft this year, but all that shows is how far Apple really is behind in this area. They’re still making rookie mistakes that Microsoft sorted out years ago.

  24. All software has bugs. Unlike Windows, OS X comes with many OSS parts, which get patched regularly by their makers. This is just about Apple and the part makers being swifter at patching their stuff than Microsoft. Besides, counting vulnerabilities is nonsensical if you don’t rate the seriousness of those vulnerabilities at the same time.

    Fact is that Mac users have practically zero security issues while Windows sufferers have to stay on their toes all the time. Period.

  25. Realist, Pete, Zune Tang etc have to realise one thing.

    Macs are Secure by design as the OS got developed for security from the ground up. The whole OS is based around the Mach kernel which is tiny and has absolutely no useless code. The rest of the functionality is provided in kexts and other libraries rather than being compiled into the kernel.

    On Windows However there are certain vulnerabilities which will never get secured without a total OS re-write as it will kill backward compatibility so you have to rely on Security companies to secure against it. They make a killing out of these these vulnerabilities from you suckers. I wouldn’t be surprised when there’s a slow month for viruses and worms if these companies didn’t write their own exploits and release them.

    Windows has had to be backward compatible for so many years now that it’s full of spaghetti code written by underpaid, undervalued de-moralised programmers who have since moved on from Microsoft. As a result it’s become useless on the internet out of the box without gatekeeper apps running constantlty taking up valuable processor cycles and interfering with internet clients and services like email to the point of unsuitability it’s a wonder that governments don’t insist that it is banned on the Interweb until it’s fixed.

    As Apple’s functionality is mainly kept out of the kernel it’s far easier to repair any vulnerabilities when they creep up so Apple do so promptly. That’s why Apple are able to keep on top of vulnerabilities and Micro$oft aren’t

    Basically You’re just uppity kids who’s toy Windows are broken. Face it and move on.

    Get a Mac or at the very least, install a flavour of Linux if you’re too tight to get a real computer like a Mac.

  26. Maybe if ol’George had actually read the Secunia website he might have seen things a bit differently.

    According to Secunia:

    Mac OS X had 26 advisories in 2007, 6 of which remain unpatched

    Windows Vista had 17 advisories in 2007 (and this part is interesting they shift to percentages for those critical and those non-criitical)

    Windows XP had 30 advisories in 2007 (same deal as vista)

    George:, uh buddy, maybe you need some glasses?

  27. PS

    The Microsoft Windows Vista and XP do not show what advisories are patched and fixed on the by vendor pages, so I’m not sure if that is a different person writing up the statistics or whether MS had not bothered to patch theirs.

    XD

  28. lol, even I was screaming “FUD” when I read Ou’s article yesterday. Microsoft has been playing this game with Linux for a while now…I’m surprised it took so long to get to Apple ” width=”19″ height=”19″ alt=”smile” style=”border:0;” />

  29. Please ignore this idiot. Don’t give him any web hits that he can make any financial claims on. This guy is an obvious troll that doesn’t deserve our attention. Move along. There’s nothing to see here folks.

  30. And once again:
     “ZDNet – the «Zune» of tech reporting.”

    And once again, the Winodze fanbois are really vicious today. I smell fear. Except for the one or two script-kiddies using their lunch hours to post about pwning us. Go for it, noob — and I’ll follow the trail back to your basement lair to smash your Twinkies…

  31. @Archibald

    Sorry to inform you there is no
    information of that nature on my machine.
    Nor has there been.

    Obviously you didn’t get into my machine.

    thx 4 trying

    I will say one thing. I was surprised that you mentioned about the police. For a second I thought you figured something out. Wrong division. Try Metro next time.

    Ron

  32. Lastly,

    It was nice meeting you Archie.

    Now we all know what’s in your minds eye, your sub-conscience thoughts and generally the type of person you are.

    The Macintosh community will not accept your type lightly.
    You have tarnished yourself. And should join in the ranks with George Ou.

    Thanks again for participating.

    r

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.