Mac OS: More critical flaws than Windows in 2007

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

Apple Mac operating systems had more critical vulnerabilities reported in 2007 than Microsoft's operating systems, according to research.

George Ou, a writer for ZDNet.co.uk's sister site ZDNet.com, analysed in-depth statistics from security research company Secunia as a basis for his research. He found that Apple's latest operating system, Mac OS X, faced more critical flaws than Windows XP and Vista combined.

While Mac OS X had 234 highly critical vulnerabilities reported in 2007, Vista and XP combined had 23, Ou wrote.

"This shows that Apple had more than five times the number of flaws per month than Windows XP and Vista in 2007, and most of these flaws are serious," wrote Ou. "Clearly this goes against conventional wisdom."

Macs have traditionally been viewed as suffering from fewer vulnerabilities than Windows.

Ou made the comparison as an indicator of how many vulnerabilities might exist in 2008, rather than a comparison of the relative security of the operating systems. He said that security had improved with both Windows Vista and Mac OS X Leopard (version 10.5) this year.

Read this

Q&A
Q&A: When more bugs can mean tighter security

Mozilla Europe's president Tristan Nitot explains why having fewer disclosed vulnerabilities doesn't mean Internet Explorer is safer than the open-source web browser

Read more +

Some experts have said that counting vulnerabilities is not necessarily reliable as a measure of security.

Tristan Nitot, president of Mozilla Europe, told ZDNet.co.uk this month that it was more important to take into account the time it takes to patch vulnerabilities.

The amount of exploit code available in the wild also has an impact on security. While there are thousands of pieces of code that seek to exploit Windows XP vulnerabilities, exploit code for Mac OS X is relatively rare.

Talkback

The count may be correct, but it fails to take into account those people running XP without SP2, or SP1. What about people still running 98SE?
These are vulnerabilities that will never be fixed. Plus Microsoft tends to bundle patches together with no information on what is being patched, so you have no idea how many problems are taken care of, just hope they got them all and that the patches aren't broke.

ator1940 20 December, 2007 14:08
Reply

"Microsoft tends to bundle patches together with no information on what is being patched, so you have no idea how many problems are taken care of, just hope they got them all and that the patches aren't broke."

Is that a fact? Amazing what one can turn up when one does a search of Microsoft's knowledge base...

Windows XP SP2 fixes

838199 - List of Internet Explorer fixes in Windows XP Service Pack 2
838200 - List of multimedia fixes in Windows XP Service Pack 2
838202 - List of Remote Desktop fixes in Windows XP Service Pack 2
838203 - Shell fixes in Windows XP Service Pack 2 and in Windows XP Tablet PC Edition 2005
838206 - List of printing fixes in Windows XP Service Pack 2 and in Windows XP Tablet PC Edition 2005
838209 - List of Microsoft Data Access Components (MDAC) fixes in Windows XP Service Pack 2 and in Windows XP Tablet PC Edition 2005
838210 - List of the management and administration issues that are addressed in Windows XP Service Pack 2 and in Windows XP Tablet PC Edition 2005
838211 - List of Com+ fixes in Windows XP Service Pack 2 and in Windows XP Tablet PC Edition 2005
838213 - List of base operating system fixes in Windows XP Service Pack 2 and Windows XP Tablet PC Edition 2005
838214 - List of the program compatibility problems and the update scenarios that Microsoft Windows XP Service Pack 2 fixes
838193 - List of Windows XP Media Center Edition fixes in Windows XP Service Pack 2

SMS SP5

816549 - List of Bugs Fixed in Systems Management Server 2.0 Service Pack 5
816290 - List of security changes in Systems Management Server 2.0 Service Pack 5

Windows 2000 SP4

327194 - List of bugs that are fixed in Windows 2000 Service Pack 4
324953 - List of Security Fixes in Windows 2000 Service Pack 3

And the list continues.

Care to revise your BS statement?

SobeLizard 20 December, 2007 19:37
Reply

When your computer alerts you that updates are being installed, and you click on the balloon, do you see a description of each update, and an explanation? No, you see,"this update fixes a vulnerability in IE7 that may allow your computer to be accessed by unauthorized personnel." This is from Microsoft.com in 2006:
As part of Microsoft's routine, monthly security update cycle, we released the following security updates on November 14, 2006:
MS06-066 - addresses a vulnerability in Microsoft Windows
MS06-067 - addresses a vulnerability in Microsoft Internet Explorer
MS06-068 - addresses a vulnerability in Microsoft Windows
MS06-069 - addresses a vulnerability in Microsoft Windows
MS06-070 - addresses a vulnerability in Microsoft Windows
MS06-071 - addresses a vulnerability in Microsoft XML Core Services
How many people check the knowledge base BEFORE installing updates?

ator1940 21 December, 2007 15:30
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Jonathan Hassell

You can find more information on BS 8878 by Jonathan Hassell its lead-author at http://www.hassellinclusion.com/bs8878/ The page includes a...

10 hours ago by Jonathan Hassell on BSI publishes first British web accessibility standard
servermanagement

Thanks for this list. Now I know, what to include on my system to make it more functional.

10 hours ago by servermanagement on Ten flawed products that derail productivity
1000092626

What if it's a 4 car household? The point is, more bandwidth = more things you can do simultaneously, like streaming HD video in one room of the...

11 hours ago by 1000092626 on Virgin Media beats 100Mbps schedule, hikes prices
Gary Burton

No point whatsoever increasing broadband download speed. unless ever server on the net has access to massively up rated throughput. The worlds...

11 hours ago by Gary Burton via Facebook on Virgin Media beats 100Mbps schedule, hikes prices
Random_Error

They're also increasing their TV package prices, whether to help fund this or not.

13 hours ago by Random_Error on Virgin Media beats 100Mbps schedule, hikes prices
Techs UK

How can you set it up wrong to intermittently connect? Should I be asking for more pay? Outlook/Exchange is a breeze.

16 hours ago by Techs UK on Ten flawed products that derail productivity
JamesCheese

And how much did Microsoft pay you for that article?

16 hours ago by JamesCheese on Time for an evil umpire: Google, Microsoft & privacy
JamesCheese

"But how many times have you seen someone make a video call from a tablet?" I do myself a lot. "How often have you seen someone hook up a tablet...

16 hours ago by JamesCheese on Apple and Amazon's tablet rivals don't get it
k0tcs3

I have to disagree with this article. Maybe there is a cultural difference between the US and UK, or maybe your network of friends is less...

17 hours ago by k0tcs3 on Apple and Amazon's tablet rivals don't get it
filthylooker

My thoughts are that there's some space for change in the business world for tablets as destop replacements. I'd contend that the tablet has a...

20 hours ago by filthylooker on Apple and Amazon's tablet rivals don't get it
emrahatilkan

Adobe did not dropped AIR development. It was Flex.

21 hours ago by emrahatilkan on Flash 11 and AIR 3 get a release date
dd2

Company called Synergix ( www.synergix.com ) has a fix for the offline folders issue experienced by Win 7 users. And you can check out...

21 hours ago by dd2 on VPNs, offline files and the simple Windows 7 fix; sometimes
Neil Lawther

I think all your above points are increasingly more invalid. The android ecosystem is open and evolving and maturing day by day. developers are...

22 hours ago by Neil Lawther via Facebook on Apple and Amazon's tablet rivals don't get it
David Meyer

That really is what the European Commission is telling me. To give a precise quote: if a member state turns down the agreement, "ACTA will stay a...

1 day ago by David Meyer on ACTA's EU future in doubt after Polish pause
MyProffs Proffs

Apple devices are back online in German, take the down, no put them back...

1 day ago by MyProffs Proffs via Facebook on German iPhone, iPad sales temporarily banned
Fat Matt

AAAAAAAAWWWWW MAAAAAAANNN, I spent nearly a grand on my pc now it's gonna be completely outdated.

1 day ago by Fat Matt on Clever on-off switch for graphene. Transistors next?
Vanessa Deagan

I completely disagree with this article. I believe the reason why Google are not successful in the tablet space is because of two reasons: 1....

1 day ago by Vanessa Deagan via Facebook on Apple and Amazon's tablet rivals don't get it
servermanagement

Bravo Infiniserv! Virtual Private Server looks promising and very useful for companies who can't really afford a expensive cloud computing software.

1 day ago by servermanagement on Infiniserv launches Linux-based UK cloud
oneoffreader

Agree with Thinklog, Voice and video talk has been a key feature between all my friends who also use tablets.

1 day ago by oneoffreader on Apple and Amazon's tablet rivals don't get it
Thinklog

Thank you for your article. However, Sir, I must disagree. I regularly use my iPad to make video calls via Skype, and I see no reason to claim that...

2 days ago by Thinklog on Apple and Amazon's tablet rivals don't get it