[funsec] Microsoft announce most secure OS on the planet
security curmudgeon
jericho at attrition.org
Wed Apr 15 19:32:37 CDT 2009
: >> For the sake of common sense, what is the distribution of IE8?
:
: Are you saying that more popular products have more vulnerabilities? I
: don't understand the question? And IE8 was in widespread beta since over
: a year ago.
Dodge .. dodge .. evade!
"Popular" products have more published vulnerabilities, that would be
pretty easy to argue. May have to qualify "popular" to who though (the
researchers/blackhats, or the general public which makes them appealing
targets to the bad guys, etc).
"widespread beta" for a year isn't the same as it being the default
browser for every Windows user for a year.
It was less a question, more a statement, that it's the same cycle: MS
says 'most secure' before product is widely deployed and well researched,
vulnerabilities are found, X months later it's just another bug ridden
product and everyone seems to have forgotten the sales-y claims made
previously.
More information about the funsec
mailing list