Microsoft Vista six-month analysis

Analysis
Jun 26, 20072 mins

The security flaws found in Vista’s during its first six months remains the subject of much comment in the blogosphere. The full report was chock full of interesting commentary that does offer some flavor of what Microsoft’s security folks are up against. For instance it reports:

“The recently published Microsoft Security Intelligence Report indicates that new vulnerability disclosures increased by 41% in 2006 and the increase from 1528 vulnerability disclosure in 2001 to 6566 disclosures in 2006 represents a cumulative annual growth rate (CAGR) of nearly 34% – consistently high.”

The report card, however, was written by CSO Security Guy Jeff Jones, who says that the increased rate of discovered vulnerabilities is because security researchers are heads down, looking for flaws. And that in turn makes any sane person wonder if all this effort at finding flaws is time well spent. In some ways, the researchers are doing the work for the bad guys. While it is true that keeping a flaw quiet until a patch can be created is a step in the right direction, much unpatched software, now with widely publicized flaws found by researchers, still seems to be tipping the scales toward hackers.

Jones makes the case that Vista has had fewer high severity bugs reported than has been found in competing operating systems in this same time frame. But it is a leap of logic to say that this somehow indicates that Vista is more secure. Most of corporate America is not yet using Vista making it less attractive for both hackers and researchers to pursue. In fact, the Microsoft Subnet previous post on the report caused a snort from at least one reader.