Account Links: Cart | Your Account

Skip to content

Rate this page del.icio.us  Digg slashdot StumbleUpon

Bug fix scorecard

by Ruth Suehle

The score is Linux: lots, Microsoft: zero

A Microsoft vulnerability report suggests that Microsoft wasn’t able to fix more Windows flaws than the number of open software flaws fixed by the major open source companies. Red Hat, having forty times less employees than Microsoft, did the best job, by fixing and closing the most security bugs, also closing even minor bugs - where Microsoft didn’t even fix one minor bug in the same period.

Read the vulnerability report.

vulnerability chart

8 responses to “Bug fix scorecard”

  1. Maddog says:

    Excellent reverse spin on Microsoft’s data! This just goes to show that Microsoft is spinning data to make its products look good. Jeff Jones should stop pretending he’s a security guy and proclaim himself as Microsoft’s marketing guru, their UberFUDMeister!

  2. Josh says:

    So, uh, is Microsoft’s numbers so low because substantially fewer vulnerabilities were discovered, or was it because they are slow to fix things. From other posts on Jeff’s blog concerning days of vulnerability, MS also comes out in the lead, suggesting that they are fixing the bugs as they arise rather than avoiding fixes.

    Also, isn’t it a bit misleading to suggest that Red Hat, with 1/40th the employees is actually fixing all of those vulnerabilities. I mean, shouldn’t some credit go to the FOSS community that also contributes to fixing vulnerabilities rather than giving redhat all of the credit.

  3. Alan says:

    Ummm. So since Red Hat had more vilnerabilities than Microsoft, they did a better job?? That’s the way to spin it. :)

    Now if they had the same vulnerabilities discovered and one fixed more than the other, then that is a win. Otherwise Windows Vista is the clear winner here for not having much to fix.

  4. Maddog says:

    Vista not having much to fix? Or isn’t it more like they don’t announce everything they try to fix? Microsoft has a history of not disclosing bugfixes (see “Skeletons in Microsoft’s Patch Day closet”; http://blogs.zdnet.com/security/?p=316) and this controversial practice will definitely skew Jeff’s numbers. That renders Jeff’s “scorecard” practically useless.

  5. Wilsonz says:

    This post looks like FUD to me or at least its a great example statistics published in an incomplete manner. The same data published as a ratio of fixes by category to bugs found would tell the story more accurately. Maddog’s post addresses the other reason this comparison is likely invalid.

  6. totalnetsolutions.net » Microsoft VS. Red Hat - Why did they go there? says:

    […] I saw this post from Jeff Jones over at Microsoft today. He mentions that Red Hat Enterprise Linux 4 recently patched their 1000th vulnerability, and provides a quote from Truth Happens(direct link to post), which is a Red Hat blog. I suggest you at least read Jeff’s post, since he quotes the relevant point of the Truth article. […]

  7. Mark Ryder says:

    You guys are amazing, thinking that fixing more bugs is a good thing. What are you doing to reduce the number of security bugs in the first? Shipping junk, and fixing lots of bugs later is simply “cowboy coding” and nothing to be proud of.

  8. Security Spin Cycles - The Capslock Assassin says:

    […] Jeff Jones posted a blog entry to celebrate Red Hat fixing their 1000th unique security vulnerability.  He also draws attention to a Red Hat post on their “Truth Happens” blog back in August, which itself quotes a post on Lxer.com. […]

Leave a reply

Subscribe


more RSS feeds

Now playing


Quicktime | Real
Real Stream | Ogg Theora

Recent postings

Secure without secrets

The death of software patents?

Wikipedia Tries Approval System to Fight Vandalism

More on GPL-compliant patent settlement

OOXML soldiers on.

Posts by category

Monthly archives

More info

Leadership
Public policy

Red Hat Press
Red Hat Magazine
Dev Fu
Red Hat People

Search our archives

Entries (RSS) and Comments (RSS). Truth Happens is powered by Lyceum and WordPress.


Copyright © 2007 Red Hat, Inc. All rights reserved.
Valid XHTML : Privacy Policy : Terms of Use : Patent promise : Company : Contact