Vista as insecure as Windows 2000

May 9, 2008, 01:48 PM —  Techworld.com — 

Good news for users of Windows Vista. According to figures compiled by PC Tools,
the OS has experienced only slightly more vulnerabilities than Windows 2000,
which appeared eight years ago when malware was far less common.

Or is that the bad news? Despite having a reputation as the least vulnerable
of Microsoft's operating systems, Vista still managed to record 639 unique vulnerabilities
over roughly the last half year, which puts it in a worse position than the
aging Windows 2000, which experienced 586 over the same period.

Windows XP, which still accounts for the overwhelming volume of the Windows
user base, had 1,021, with Windows 2003 Server reaching 478.

The Australian security company collected statistics on the number of infections
by analyzing figures from anonymous users of its ThreatFire community, with
vulnerabilities double-confirmed by third-party anti-virus engines. The numbers
are per 1,000 machines on each platform.

"Microsoft has invested a great deal in making Vista more secure, by providing
a number of security enhancements which were not in prior Microsoft operating
system releases," concluded PC Tools CEO, Simon Clausen. "But industry
experts have been reluctant to confirm its improved resistance to malware with
good reason."

"Since its launch, Microsoft has flagged the increased level of protection
Vista provides as one of the key reasons why consumers should upgrade from Windows
XP to Vista. If Microsoft's forecasts for the operating system are correct and
Vista's market share increases significantly, we could expect infection rates
to increase further on Vista," he added.

The problem with these bare statistics is that they make no mention of how
serious these vulnerabilities were -- Vista has recorded few that come into
the 'most serious' category by comparison with XP. They also don't specify where
the vulnerabilities were uncovered. The majority of vulnerabilities are not
in the OS itself and are traced to problems in browsers, for instance, and can
even apply across platforms.

Microsoft would also point out that the user access control (UAC) feature of
Vista stops malware from exploiting the OS without the user at least being aware
that something is happening. Windows 2000 and XP lack even this basic level
of protection.

On the other hand, Vista has had its embarrassing moments, securitywise. Only
weeks ago, Microsoft had to explain how the .ANI animated cursor bug was allowed
to find its way into Vista code without being patched as part of the much-vaunted
Security Development Lifecycle (SDL).

» posted by abennett

Techworld.com

I like it!
Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
Free stuff

Win an Amazon Kindle!
This month's giveaway gadget - Amazon's Kindle - will keep you entertained on the long trip home to visit family and friends over the holidays. Enter the drawing now!

Applied Security Visualization
By Raffael Marty
Published by Addison-Wesley Professional
Learn more!

 

IT Manager's Handbook
By Bill Holtsnider and Brian D. Jaffe
Published by Morgan Kaufmann
Learn more!

 

Windows Vista Resource Kit
By Mitch Tulloch, Tony Northrup, and Jerry Honeycutt
Published by Microsoft Press
Learn more!

Featured Sponsor

AISO founders envisioned a Web hosting company that was environmentally friendly. While the company employed energy-efficient innovations like solar panels, its infrastructure produced unacceptable power and cooling requirements. Find out how AISO leveraged AMD technology to overcome their challenge in this case study white paper.

In this whitepaper, Scalar explores the opportunity to change the landscape with respect to mission critical databases built around Oracle. Leveraging technologies such as Linux, high-end commodity processing power and Oracle RAC technology to architect, design, build and maintain database infrastructure that delivers maximum availability, reliability and performance at a fraction of traditional cost.

On a typical day, weather.com, the Web site for The Weather Channel in Atlanta, serves up between 15 million and 20 million page views. But in September 2004, when back-to-back hurricanes ransacked Florida, the peak traffic on one day more than tripled: over 70 million page views by more than 7 million unique visitors. Read the full success story now.

More Resources