“During 2007, Apple has patched more than ten times the number of critical vulnerabilities in Mac OS X compared to the number patched in Microsoft Windows,” Tom Espiner reports for ZDNet UK. “George Ou, a writer for ZDNet Australia sister site ZDNet.com, analysed in-depth statistics from security research company Secunia as a basis for his research.”
MacDailyNews Take: ROTFLOFAO, he called what Ou does “research!” Please see related articles:
• ZDNet’s George Ou Exposed as Ignorant Microsoft Shill – RoughlyDrafted
• George Ou’s Greatest Apple Hits! – The Macalope
• George Ou: When Gerbilling isn’t fun enough – Artie MacStrawman’s Apple Orchard
• George Ou’s Bad Idea: Comparing Apple Ads to Nazi Propaganda – Wired
Espiner continues, “He found that Apple’s latest operating system, Mac OS X, faced more critical flaws than Windows XP and Vista combined… Ou made the comparison as an indicator of how many vulnerabilities might exist in 2008, rather than a comparison of the relative security of the operating systems.”
“Some experts have said that counting vulnerabilities is not necessarily reliable as a measure of security,” Espiner reports. “Tristan Nitot, president of Mozilla Europe, told ZDNet.co.uk this month that it was more important to take into account the time it takes to patch vulnerabilities.”
Espiner reports, “The amount of exploit code available in the wild also has an impact on security. While there are thousands of pieces of code that seek to exploit Windows XP vulnerabilities, exploit code for Mac OS X is relatively rare.”
Full article here.
MacDailyNews Take: In “honor” of George Ou, we’re going to continue surfing the Internet unimpeded with our Mac OS X Firewall turned off for another six years.
Looks like he got shot by phasers on 180˚
That just means that M$ didn’t patch all theirs, not that the mac was insecure because Apple did patch a bunch.. M$ is probably still trying to figure out HOW to patch them..
Show us ANY actual users out in the wild that have ever been impacted by any of these so called vulnerabilities, and then we’ll talk….
And my boat is really water tight, because I had to patch it 34 times last year.
Apparently George Ou needs his brain patched.
It’s Mr. Zero U to the ‘rescue’ of MS and Windows’ apologists everywhere!
let him go back to Gerbilling….
It’s floating, isn’t it? Your WINDOWS boat is UNDER WATER!
I’m wondering why no one is bringing up this question:
How many of the updates issued by Apple vs. M$ would allow a malicious attacker to take over the system?
Another conspiracy attempt / FUD from the M$ proxies ie: ZNET.
A key gauge would be what actual vulnerabilities are out in the wild and being exploited.
I have a feeling the actual OSX vulnerabilities being exploited is no where close to the quantity for XP and/or Vista.
I was beginning to worry that all these reports of security issues might be true.
I too will ignore them all along with the false alarms that Apple itself sends out in the form of some ‘security updates’ to the OS and various Apple apps.
Man, do I love the Mac!
I guess Ou’s point is that he would rather have an operating system from a company which doesn’t acknowledge or correct errors rather than a company which does updates and corrections?
I think it’s rather amusing that people expect software to be perfect the first time it’s written, every time a new feature is added, etc. Software is written by people, and people are aberrated and make mistakes. Plus, a company cannot possibly test for every possible combination of software, hardware and user interaction. Thus, Apple corrects mistakes, etc. by issuing patches. And far before ANY malicious attack can be made.
It’s pretty remarkable how fast Apple had OS 10.5.1 prepared and released.
At least Apple doesn’t bury its head in the software sand and pretend the problem doesn’t exist.
Vulnerability does not equal exploit. All exploits are not equal. Macs don’t get turned into hackers’ spambots. If there are so many security issues with Mac OS X, where are all the exploits? Oh, there aren’t any, just Trojan Horse malware for the gullible and “proof of concept” stuff in the labs of security companies. Never mind…
Apple should be applauded for diligently fixing potential issues in a timely manner. The reason there have not been any meaningful exploits is because hackers can’t do anything meaningful (worth their time and effort) with these so-called “critical vulnerabilities.” The low-hanging fruit will always be Windows.
The one thing I love about apple is that they continue to patch – update there OS’s incrementally. I’ve only been a Mac user since panther and I can’t believe how responsive they (apple) are.
It’s great that they come out with the updates as often as they do, but I still do a backup before I install. I usually just wait till the weekend since I do my weekly Super Duper backup then. You never know when one of these things can cause problems. Better safe than sorry.
When will these idiots learn that vulnerabilities are not exploits?
A vulnerability is a potential problem. When someone takes advantage of a vulnerability, then it becomes an exploit.
I sometimes leave my house unlocked when I go out. That’s a vulnerability. I have two German Shepherd Dogs inside the house. there have never been any exploits.
The difference between Apple and Microsoft here is, Apple actually fix majority of the holes before someone exploits them, and Microsoft waits until 50% of windows user have some sort of virus. Even then they still leave it up to the anti-virus programs.
My Macs are very secure, self aware, and have high moral values.
My PCs have self esteem issues and criminal tendencies.
Don’t believe the hype. The shepherd has pulled the wool over your eyes for too long.
This article tells the truth.
MDN is blind to the truth.
The moron needs a logic patch!
ROTFLMAO! That guy HAS to be on heavy duty drugs! What a tool!
The keyword is ZDnet, which is worse than even Cnet if thats possible. These guys are real scum suckers. their breath smells like farts.
@ Realist
Perfect.
Realist = Pete
This BS stinks so bad even Ou couldn’t put his name on it!
I addressed Microsoft’s disgusting tack of redefining security via any measure other than attacks in the wild a while ago:
Microsoft: Building better security through statistics.
His articles are more SNAPPY these days!
Comparing security by counting vulnerabilities, but ignoring actual exploits makes as much sense as comparing smart phones by counting features, but ignoring whether people can satisfactorily use those features in the real world.
Amazing, new Mac user here, you all make up explainations to justify your beliefs that Apple can do no wrong.
sounds like religion, is this a cult thing?
example:
A key gauge would be what actual vulnerabilities are out in the wild and being exploited.
why does this matter, I hack, I tell no one my exploits don’t make virus either to have get out of control.
give me your ip address, I;ll get in your machine
SSH is open by default on Mac’s, people make up easy to guess passwords. simple dictionary attack I pwned you.
“In “honor” of George Ou, we’re going to continue surfing the Internet unimpeded with our Mac OS X Firewall turned off for another six years.”
LOL… excellent. Lets email Ou that we’re all going to do this.
Idiots,
Microsoft pays security companies to look for and publicize security holes in Mac OS X so the vulnerability patch count of Mac OS X vs Vista makes Vista somehow look better.
The truth is, with what few security holes there were in OS X already patched, OS X is very secure.
Vista, on the other hand, is full of secret, legacy code that is full of undiscovered vulnerabilities just waiting to be found and exploited.
Let’s compare exploits or unpatched, unfound vulnerabilities. There’s no way Vista wins that game.
ya know, it’s funny. i go to hardocp.com quite a bit, and they reported on this too – of course, they didn’t actually think about it when they posted it, they just said something like “so much for most secure OS in the world!” – they have a lot of information and news that i enjoy reading but their anti-apple bias actually manages to be more irritating than the anti-MS bias here – mostly because at least the anti-MS stuff here has some basis in REALITY, instead of just in theory. MDN’s take is awesome, and i’ll be joining them in not worrying about my built-in firewall (four years of OS X for me and not one security/virus/malware issue the whole time).
as for hardocp: they can stfu and enjoy running ad-aware and spybot and AVG while i actually get some web surfing done!
>>we’re going to continue surfing the Internet unimpeded with our Mac OS X Firewall turned off for another six years.<<
Not me. I’m having my firewall turned on. Also on my servers both Ubuntu Linux and FreeBSD the firewalls are always on….. Also my router has a built in firewall which is….. yes you guessed it: always on
Having a firewall and not using it is plain stupid….
Archie the new Mac user,
Do you also want the keys to my house and car? Neither has an alarm system.
Archie the new Mac user,
Welcome <arms out and lips puckered> Yes, this is a cult. Did you get a tatto yet? What flavor Kool-Aid do you like? We’ll talk later over a tofu lunch, OK?
“give me your ip address, I;ll get in your machine”
I hope you’re better at terminal commands than spelling and grammar.
;-p
I’m game… you proclaim:
“SSH is open by default on Mac’s, people make up easy to guess passwords. simple dictionary attack I pwned you.”
Do your stuff, get into my machine, impress me
“Do you also want the keys to my house and car? Neither has an alarm system.”
No, just leave the doors unlocked for us, because that’s the equivalent of going on the Internet without a firewall and anti-malware protection.
I know, in sleepy little MacTown where you live you don’t get much crime, so the population feels safe and secure for now with the doors wide open, no alarm systems and the locks not working even if you did choose to close the doors.
Twenty three years and no problems yet.
That’s all I need to know.
we’re going to continue surfing the Internet unimpeded with our Mac OS X Firewall turned off for another six years.
Do you also drive without seat belts because your car has a great safety rating?
Some risks aren’t worth taking.
“Do you also drive without seat belts because your car has a great safety rating?”
Only if I can light a bowl while straddling a six-pack and text messaging my Congressman.
“Twenty three years and no problems yet. That’s all I need to know.”
I think that’s what the Indians said before European disease came to their peaceful little world.
Don’t forget that one of those European diseases was compulsive gambling. Sweet irony.
George “Ou NO HE DIT’NT!!!!”
“activity”- that of which there is none in Mr. Ou’s brain…
Ampar,
Is the compulsive gambling disease spread through bodily fluids?
LorD1776: Odds are . . .
I don’t get the mentality of people that could have enjoyed the last 20+ years of relatively virus free existence with Apple’s Macintosh but consciously chose not to and continue to do so.
Instead they insist on crying “the sky is falling” if there is a possible virus threat on the Mac. Meanwhile, they have had to put up with over 100,000 virus’ on a Microsoft Windows PC – the endless supply of Windows malware And pathetic Anti-virus support that Microsoft has sold them. – I mean, Microsoft actually sold it instead of just including it as part of the OS. That in itself is worthy of a “WOW”. How pathetic is that of Microsoft? Very!
Still, the Mac in comparison to the PC is completely virus free. Why wouldn’t you want to be a part of that? I certainly enjoy that aspect of the Mac.
The Mac has a Long Long way to go to catch up to Windows in the virus world – and so far Windows has maintained a very “unhealthy lead”. A lead Microsoft doesn’t appear to be able to relinquish.
Security through obscurity? – Whatever – that’s perfectly fine with me whether it’s true or not. It’s more secure. I’ll take it. You would be a fool not to.
>>Let’s compare exploits or unpatched, unfound vulnerabilities. There’s no way Vista wins that game.
That is illogical, Captain. You cannot compare unfound vulnerabilities as you have nothing to compare.
Apple CHOOSES to stay on top of things
RATHER then be moved over by hacking hell raisers PAID by MacroSloth and it’s team of Anti-virus sellers.
See Apple care about it’s status and will continue.
MacroSloth sits and basks it’s glory dreaming up useless plots to invade Apple.
They laugh in fear knowing soon their time will end shortly.
THEY are insecure over there at Macrosloth stink.
jay and my pointed plunger
All this back and forth mud-slinging is actually part of Steve’s evil plan for global domination.
He is siccing the journalists and the die-hard fans on each other. Once the swirling vortex of cynical-obsessive deconstructionism vs. rabid loyalty reaches critical mass, the two will react and go supernova, destroying both groups and clearing the way for total world control.
Trust me
TRY me
I LOVE to PROVE you wrong.
AND ALL OF US HERE will LAUGH your useless hacking abilities.
COME ON
HERE
99.235.255.182
GET IN WRITE me a TEXT MESSAGE using my TEXTEDIT
and a huge smilie
Ron
should have wrote last POST… @Archie.
STILL OPEN for your hacking skills
amuse me…
I don’t even have a PASSWORD
come on buddy lets see the big man walk his talk
Is this like combining matter and anti-matter? There will be no world left to control.
my machine is on for your musing
lets play ball dick.
WHILE your attempting… remind yourself that I will be pulling your IP with custom tracing software that I personally wrote…
I will OWN U… Archibald !
LET PLAY
is a beaver head
come on
“Amazing, new Mac user here, you all make up explainations to justify your beliefs that Apple can do no wrong.
sounds like religion, is this a cult thing?
example:
A key gauge would be what actual vulnerabilities are out in the wild and being exploited.
why does this matter,”
are you really that stupid? you have to have that explained to you?
The main reason for the mac having more known vulnerabilities is the fact that most components of OSX are open source. So the code can be audited by anyone. Therefore windows could have more vulnerabilities then osx as their code is not accessble by anyone but Microsoft. As Microsoft has been known to patch vulnerabilities secretly i wouldn’t be surprised if there is more.
I would have thought the real measure/s of security are:
1. Percentage of users impacted
2. Average degree (and maybe duration) of impact
MacDailyNews Take: Pass the red Kool-aide. Take a long drink… You will not feel a thing!
Daniel Eran Dilger at Roughlydrafted Magazine ROCKS !!!
While most users will be familiar with ROUGHLYDRAFTED, new users like Archie and others need to pay Dan’s site a visit to educamate themselves.
did you hear that thinksecret is shutting down?
99.235.255.182 = kiddie porner
I’d say u got 24-36 hours before knock on door from FBI..
hahaha, Mac fool. happy zeroing,better make that a 35x overwrite if i was u….
i get in any machine…
99.235.255.182 =
http://www.rcmp-grc.gc.ca/wanted/widziak_e.htm
coming for u, run chicken…
“Security through obscurity? – Whatever – that’s perfectly fine with me whether it’s true or not. It’s more secure.”
Security through obscurity is regarded by any security professional as no security at all.
Say all you like that it’s good that Apple has had 10 times the vulnerabilities of Microsoft this year, but all that shows is how far Apple really is behind in this area. They’re still making rookie mistakes that Microsoft sorted out years ago.
All software has bugs. Unlike Windows, OS X comes with many OSS parts, which get patched regularly by their makers. This is just about Apple and the part makers being swifter at patching their stuff than Microsoft. Besides, counting vulnerabilities is nonsensical if you don’t rate the seriousness of those vulnerabilities at the same time.
Fact is that Mac users have practically zero security issues while Windows sufferers have to stay on their toes all the time. Period.
Regarding security, an IP address is an IP address. Come and get us, Windows’ neotards . Hear that, George Zero-u?!
Realist, Pete, Zune Tang etc have to realise one thing.
Macs are Secure by design as the OS got developed for security from the ground up. The whole OS is based around the Mach kernel which is tiny and has absolutely no useless code. The rest of the functionality is provided in kexts and other libraries rather than being compiled into the kernel.
On Windows However there are certain vulnerabilities which will never get secured without a total OS re-write as it will kill backward compatibility so you have to rely on Security companies to secure against it. They make a killing out of these these vulnerabilities from you suckers. I wouldn’t be surprised when there’s a slow month for viruses and worms if these companies didn’t write their own exploits and release them.
Windows has had to be backward compatible for so many years now that it’s full of spaghetti code written by underpaid, undervalued de-moralised programmers who have since moved on from Microsoft. As a result it’s become useless on the internet out of the box without gatekeeper apps running constantlty taking up valuable processor cycles and interfering with internet clients and services like email to the point of unsuitability it’s a wonder that governments don’t insist that it is banned on the Interweb until it’s fixed.
As Apple’s functionality is mainly kept out of the kernel it’s far easier to repair any vulnerabilities when they creep up so Apple do so promptly. That’s why Apple are able to keep on top of vulnerabilities and Micro$oft aren’t
Basically You’re just uppity kids who’s toy Windows are broken. Face it and move on.
Get a Mac or at the very least, install a flavour of Linux if you’re too tight to get a real computer like a Mac.
Maybe if ol’George had actually read the Secunia website he might have seen things a bit differently.
According to Secunia:
Mac OS X had 26 advisories in 2007, 6 of which remain unpatched
Windows Vista had 17 advisories in 2007 (and this part is interesting they shift to percentages for those critical and those non-criitical)
Windows XP had 30 advisories in 2007 (same deal as vista)
George:, uh buddy, maybe you need some glasses?
PS
The Microsoft Windows Vista and XP do not show what advisories are patched and fixed on the by vendor pages, so I’m not sure if that is a different person writing up the statistics or whether MS had not bothered to patch theirs.
XD
lol, even I was screaming “FUD” when I read Ou’s article yesterday. Microsoft has been playing this game with Linux for a while now…I’m surprised it took so long to get to Apple
” width=”19″ height=”19″ alt=”smile” style=”border:0;” />
Knows All: Your stash came from Belize, right?
Please ignore this idiot. Don’t give him any web hits that he can make any financial claims on. This guy is an obvious troll that doesn’t deserve our attention. Move along. There’s nothing to see here folks.
And once again:
“ZDNet – the «Zune» of tech reporting.”
And once again, the Winodze fanbois are really vicious today. I smell fear. Except for the one or two script-kiddies using their lunch hours to post about pwning us. Go for it, noob — and I’ll follow the trail back to your basement lair to smash your Twinkies…
Ahem, since when did “security by obscurity” refer to the Mac or any other open source based OS?
Look up the meaning of the phrase on wikipedia. It totally refers to Microsoft OS’s. And yes. It’s NO security!
“It totally refers to Microsoft OS’s”
It’s a generic security term.
So you have the entire source code for Mac OS X and have reviewed it for all vulnerabilities? Good for you.
@Archibald
Sorry to inform you there is no
information of that nature on my machine.
Nor has there been.
Obviously you didn’t get into my machine.
thx 4 trying
I will say one thing. I was surprised that you mentioned about the police. For a second I thought you figured something out. Wrong division. Try Metro next time.
Ron
Lastly,
It was nice meeting you Archie.
Now we all know what’s in your minds eye, your sub-conscience thoughts and generally the type of person you are.
The Macintosh community will not accept your type lightly.
You have tarnished yourself. And should join in the ranks with George Ou.
Thanks again for participating.
r
Windows = Swiss Cheese
OS X = Swiss Cheese
Who really gives a rats ass..?
I use both and continue to have no issues with either..
MDN = (mw) “National” retards forum
Blubber,
Maybe so, but I’ll bet they have issues with you.
Signed, Retard