<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Download: H1 2008 Desktop OS Vendor Report - Vulnerabilities and Days-of-Risk</title><link>http://blogs.technet.com/security/archive/2008/10/27/download-h1-2008-desktop-vuln-report.aspx</link><description>This report looks at all of the vulnerabilities fixed by Apple, Microsoft, Red Hat and Ubuntu during the first half of 2008. At the vendor level, the report examines all vulnerabilities as well as Days of Risk (DoR) associated with those vulnerabilities.</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Rapport sur les vulnérabilités des OS clients pour le premier semestre 2008</title><link>http://blogs.technet.com/security/archive/2008/10/27/download-h1-2008-desktop-vuln-report.aspx#3142448</link><pubDate>Mon, 27 Oct 2008 13:24:14 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3142448</guid><dc:creator>pascals.blog</dc:creator><description>&lt;p&gt;Jeff Jones vient de publier le rapport sur les vuln&amp;amp;#233;rabilit&amp;amp;#233; des OS clients pour le premier&lt;/p&gt;
</description></item><item><title>re: Download: H1 2008 Desktop OS Vendor Report - Vulnerabilities and Days-of-Risk</title><link>http://blogs.technet.com/security/archive/2008/10/27/download-h1-2008-desktop-vuln-report.aspx#3144529</link><pubDate>Thu, 30 Oct 2008 11:43:50 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3144529</guid><dc:creator>arty</dc:creator><description>&lt;p&gt;Red Hat avg DoR is 55.5 days -&amp;gt; &lt;a rel="nofollow" target="_new" href="https://www.redhat.com/security/data/metrics/summary-rhel5-all.html"&gt;https://www.redhat.com/security/data/metrics/summary-rhel5-all.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;guess that your're math is weird.&lt;/p&gt;
&lt;p&gt;probably most other stats as miscalculated as this one. like always.&lt;/p&gt;
&lt;p&gt;second, public disclosure of vulnerablities on each system is very different.&lt;/p&gt;
&lt;p&gt;also, Microsoft release fixes only once a month, that's another, that makes your DoR calculations even weirder.&lt;/p&gt;
&lt;p&gt;fair comparison between those system just can't be done, there's too many differenties to assume perfect rules for compare. it's just spreeding FUD, that's bad.&lt;/p&gt;</description></item><item><title>Очердное сравнение осей</title><link>http://blogs.technet.com/security/archive/2008/10/27/download-h1-2008-desktop-vuln-report.aspx#3144544</link><pubDate>Thu, 30 Oct 2008 12:10:53 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3144544</guid><dc:creator>Алексей Майоров</dc:creator><description>&lt;p&gt;По ссылке доступно последнее сравнение популярных операционок на предмет уязвимостей. Главные выводы&lt;/p&gt;
</description></item><item><title>re: Download: H1 2008 Desktop OS Vendor Report - Vulnerabilities and Days-of-Risk</title><link>http://blogs.technet.com/security/archive/2008/10/27/download-h1-2008-desktop-vuln-report.aspx#3144730</link><pubDate>Thu, 30 Oct 2008 17:57:13 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3144730</guid><dc:creator>Lisa</dc:creator><description>&lt;p&gt;It would be interesting to see the same type of report from someone who is not employed by MS, as I have seen quite a bit of data from independent sources that present quite a different analysis....&lt;/p&gt;</description></item><item><title>Statistiques sur la sécurité</title><link>http://blogs.technet.com/security/archive/2008/10/27/download-h1-2008-desktop-vuln-report.aspx#3146652</link><pubDate>Mon, 03 Nov 2008 21:52:30 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3146652</guid><dc:creator>WebLog de Stéphane PAPP [MSFT]</dc:creator><description>&lt;p&gt;En compl&amp;amp;#233;ment de la publication de Jeff Jones signal&amp;amp;#233;e par Pascal SAULIERE derni&amp;amp;#232;rement&lt;/p&gt;
</description></item><item><title>re: Download: H1 2008 Desktop OS Vendor Report - Vulnerabilities and Days-of-Risk</title><link>http://blogs.technet.com/security/archive/2008/10/27/download-h1-2008-desktop-vuln-report.aspx#3148210</link><pubDate>Thu, 06 Nov 2008 03:19:09 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3148210</guid><dc:creator>Rodney</dc:creator><description>&lt;p&gt;You can't seriously expect people to believe this? Microsoft only has the lowest number of vulnerabilities and quickest fixes because you *hide* the vulnerabilities until you have a patch ready, where as Linux is up front about everything.&lt;/p&gt;
&lt;p&gt;Additionally, you only include Microsoft core OS in the list of Microsoft patches. You don't include all the other Microsoft products and all the millions of applications that can be installed on Windows. Yet in Linux, you include all kinds of non-core, 3rd party applications in the list of vulnerabilities. &lt;/p&gt;
&lt;p&gt;The report is therefore, in effect, a blatant lie. And the news flash for you is, everyone knows it. So if you want Microsoft to be seen in a better light, don't try to pull the wool over people's eyes, ok?&lt;/p&gt;</description></item><item><title>re: Download: H1 2008 Desktop OS Vendor Report - Vulnerabilities and Days-of-Risk</title><link>http://blogs.technet.com/security/archive/2008/10/27/download-h1-2008-desktop-vuln-report.aspx#3148773</link><pubDate>Fri, 07 Nov 2008 01:05:42 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3148773</guid><dc:creator>jrjones</dc:creator><description>&lt;p&gt;Rodney,&lt;/p&gt;
&lt;p&gt;Let's assume for a minute that you are correct and that Microsoft only has the lowest number of vulnerabilities and quickest fixes because they hide the vulnerabilities until a patch is ready.&lt;/p&gt;
&lt;p&gt;Okay, let's say (theoretically) every issue is &amp;quot;hidden&amp;quot; for two years and then a patch is made available, making the issue public. &amp;nbsp;If true, this would simply delay the disclosure timeline for two years. &amp;nbsp;The ones disclosed in H108 would just be the ones &amp;quot;hidden&amp;quot; since H106.&lt;/p&gt;
&lt;p&gt;No matter how you look at it - the large numbers of vulns you are implying exist should show up somewhere on the timeline. &amp;nbsp;And that does not seem to be the case.&lt;/p&gt;
&lt;p&gt;You are correct that I do not include &amp;quot;all of the other Microsoft&amp;quot; products in the desktop analysis, though if you want to see the trends on *all vulnerabilities in all Microsoft products*, I encourage you to take a look at the latest &lt;a rel="nofollow" target="_new" href="http://www.microsoft.com/sir"&gt;http://www.microsoft.com/sir&lt;/a&gt; document, where I do look at those trends.&lt;/p&gt;
&lt;p&gt;You are incorrect that I include non-core Linux distro applications - I did quite a bit of work to exclude all of the non-default packages as well as some other *default* packages that don't have an equivalent include in Windows.&lt;/p&gt;
&lt;p&gt;If you want to back up your assertions and accusations, I'd love to see that. &amp;nbsp;I encourage you to perform your own analysis and publish it and I'll be happy to study it and give you my feedback as well.&lt;/p&gt;
&lt;p&gt;Thanks for coming to check out the report, even if you are doubtful about the results.&lt;/p&gt;
</description></item><item><title>re: Download: H1 2008 Desktop OS Vendor Report - Vulnerabilities and Days-of-Risk</title><link>http://blogs.technet.com/security/archive/2008/10/27/download-h1-2008-desktop-vuln-report.aspx#3155860</link><pubDate>Tue, 18 Nov 2008 20:02:30 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3155860</guid><dc:creator>jrjones</dc:creator><description>&lt;p&gt;Arty,&lt;/p&gt;
&lt;p&gt;% Red Hat avg DoR is 55.5 days -&amp;gt; &lt;a rel="nofollow" target="_new" href="https://www.redhat.com/security/data/metrics/summary-rhel5-all.html"&gt;https://www.redhat.com/security/data/metrics/summary-rhel5-all.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;gt;guess that your're math is weird.&lt;/p&gt;
&lt;p&gt;I accept that number as accurate without checking it, but that doesn't mean my math is weird. &amp;nbsp;I calculated DoR during 1H08.&lt;/p&gt;
&lt;p&gt;Check out: &lt;a rel="nofollow" target="_new" href="https://rhn.redhat.com/errata/rhel-client-workstation-errata.html"&gt;https://rhn.redhat.com/errata/rhel-client-workstation-errata.html&lt;/a&gt; and note that there were 6 advisories on the day the product shipped, fixing 37 issues. &amp;nbsp;Of course, those 37 issues contribute ZERO days of risk since the fix was available on the day of ship. &amp;nbsp;But what does that mean for DoR average going forward?&lt;/p&gt;
&lt;p&gt;Well, quickly, we can see that if the next 37 issues took 90 days to fix and only occurred 90 days after ship, that would only bring the average DoR down to 45 for all 74 issues. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;But you're telling me that the overall average is even higher than that at 55 days. &amp;nbsp;That seems to imply that there have been lots of issues that took a long time to fix and I can draw that conclusion without a ton of detailed analysis by looking the average and just the advisories on day one.&lt;/p&gt;
&lt;p&gt;% probably most other stats as miscalculated as this one. like always.&lt;/p&gt;
&lt;p&gt;Probably not, since this one isn't miscalculated either. &amp;nbsp;Go do a little bit of digging to check your assertion.&lt;/p&gt;
&lt;p&gt;% second, public disclosure of vulnerablities on each system is very different.&lt;/p&gt;
&lt;p&gt;That is true, each company *decides* its own efforts and policies and those differences do have a real impact on customer risk.&lt;/p&gt;
&lt;p&gt;% also, Microsoft release fixes only once a month, that's another, that makes your DoR calculations even weirder.&lt;/p&gt;
&lt;p&gt;I don't see weirdness, just some extra days in the calculations - pretty simple really.&lt;/p&gt;
&lt;p&gt;% fair comparison between those system just can't be done, there's too many differenties to assume perfect rules for compare. it's just spreeding FUD, that's bad.&lt;/p&gt;
&lt;p&gt;On the other hand, people do make comparisons that are even less fair and accurate than this one. &amp;nbsp;It is not acceptable to simply throw up your hands and say it isn't possible when people consider security a factor for decision making.&lt;/p&gt;
&lt;p&gt;To me, the FUD is when folks say things like &amp;quot;Linux is inherently more secure&amp;quot; without providing any support for the statement.&lt;/p&gt;
</description></item><item><title>Falla di sicurezza di Internet Explorer: disponibile la patch</title><link>http://blogs.technet.com/security/archive/2008/10/27/download-h1-2008-desktop-vuln-report.aspx#3170393</link><pubDate>Wed, 17 Dec 2008 21:00:33 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3170393</guid><dc:creator>ZenIT Blog</dc:creator><description>&lt;p&gt;Feliciano Intini sul suo blog ha annunciato che questa sera (17/12/2008) alle 19:00 sar&amp;#224; rilasciato un&lt;/p&gt;
</description></item><item><title>2008年上半期 デスクトップ OS ベンダー レポート ～脆弱性と DoR ～</title><link>http://blogs.technet.com/security/archive/2008/10/27/download-h1-2008-desktop-vuln-report.aspx#3211180</link><pubDate>Tue, 10 Mar 2009 14:01:22 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3211180</guid><dc:creator>日本のセキュリティチーム (Japan Security Team)</dc:creator><description>&lt;p&gt;小野寺です。 少し前になりますが、Jeff Jonesが、主な4つのデスクトップOSを調査して、脆弱性の対応状況等を レポートとして公表していました 。 脆弱性に対する考え方の一つとして面白いため、翻訳版を作ってみました。冒頭部分を以下に抜粋します。&lt;/p&gt;
</description></item></channel></rss>