Mailbag: Readers call into question Linux security report

Opinion
Nov 15, 20042 mins

* Reader comments flood in regarding mi2g study on Linux

Linux vs. Windows security studies always stir up a lot of emotions among newsletter subscribers, but last week’s issue about a study by British IT security research firm mi2g topped them all in terms of reader ire.

Many dozens of e-mails came in commenting on the mi2g study, which claimed that Linux was the most-attacked operating system on computers attached to the Internet. The firm claims to have examined data from around 240,000 computer hacks over the last year. It says Linux was the operating system on 65% of the incidents it looked at, while Microsoft made up 25%. FreeBSD was deemed “most secure” showing up in only 4% of the incidents studied.

Since the mi2g released its study, observers have called into question some of the firm’s methodology. The fact that the study counted breaches mainly as “manual” hack attacks on a computer and not count automated attacks spurred by viruses and Trojans, left much out of the picture. Because of this, readers were quick to call into question the credibility of mi2g.

Several readers pointed out that mi2g studies have been suspect in the past, such as previous reports that presented unrealistic numbers on the worldwide cost of cybercrime, or statistics on Web site defacements (see https://vmyths.com/rant.cfm?id=637&page=4 and https://www.attrition.org/errata/charlatan/mi2g-history.html ).

One reader wrote: “Mi2g has been duped and discredited on more than one occasion. You can skew almost any statistical analysis in the direction you wish. When reading the report, something just doesn’t add up, which makes me very skeptical about its findings and mi2g.”

Another reader says a larger pool of incidents should have been considered in the report.

“[Mi2g] analyzed 240,000 ‘digital breaches,’ what about the many millions of worm infestations over the past year?” asked another reader. “This sounds quite slanted to me – as though it culled Linux-specific incidents from a much larger data pool.”

And of course, many readers questioned the underlying motives of mi2g’s report. (What good Linux rant would be complete without Microsoft conspiracy theories?)  “I would lay even money on mi2g being funded, whether secretly or not, by Microsoft,” said this reader. “We’ve seen this too many times. Microsoft only responsible for 25% of security breaches? Puh-leez!”