<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Vista vs Mac OS X Security: Why George Ou&#8217;s ZDNet Vulnerability Numerology is Absurd</title>
	<atom:link href="http://www.roughlydrafted.com/2007/12/21/vista-vs-mac-os-x-security-why-george-ous-zdnet-vulnerability-numerology-is-absurd/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.roughlydrafted.com/2007/12/21/vista-vs-mac-os-x-security-why-george-ous-zdnet-vulnerability-numerology-is-absurd/</link>
	<description>Daniel Eran Dilger in San Francisco</description>
	<lastBuildDate>Sun, 05 Feb 2012 17:03:33 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: softwareDev78</title>
		<link>http://www.roughlydrafted.com/2007/12/21/vista-vs-mac-os-x-security-why-george-ous-zdnet-vulnerability-numerology-is-absurd/comment-page-1/#comment-29421</link>
		<dc:creator>softwareDev78</dc:creator>
		<pubDate>Mon, 07 Jun 2010 04:21:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.roughlydrafted.com/2007/12/20/vista-vs-mac-os-x-security-why-george-ous-zdnet-vulnerability-numerology-is-absurd/#comment-29421</guid>
		<description>I really like the way this article questions the absurdity and ambiguity of security flaw reporting.  While it&#039;s not easy to provide an accurate summary of security flaws, it seems clear there is an obvious bias in favor of Windows over OSX.  
As an experienced software developer and in depth user or all Windows operating systems and Apple OSX, I would state, in my humble opinion, that Apple&#039;s OS X has been far more stable and secure  than any version of Windows I have had  the misfortune of using.
This is not to say I&#039;ve never had any problems using OSX, however, I&#039;ve not experienced any security issue with OSX and I&#039;ve used all sorts of open source and third party software on it for years.</description>
		<content:encoded><![CDATA[<p>I really like the way this article questions the absurdity and ambiguity of security flaw reporting.  While it&#8217;s not easy to provide an accurate summary of security flaws, it seems clear there is an obvious bias in favor of Windows over OSX.<br />
As an experienced software developer and in depth user or all Windows operating systems and Apple OSX, I would state, in my humble opinion, that Apple&#8217;s OS X has been far more stable and secure  than any version of Windows I have had  the misfortune of using.<br />
This is not to say I&#8217;ve never had any problems using OSX, however, I&#8217;ve not experienced any security issue with OSX and I&#8217;ve used all sorts of open source and third party software on it for years.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Microsoft&#8217;s Mojave Experiment Exposes Serious Vista Problems &#8212; RoughlyDrafted Magazine</title>
		<link>http://www.roughlydrafted.com/2007/12/21/vista-vs-mac-os-x-security-why-george-ous-zdnet-vulnerability-numerology-is-absurd/comment-page-1/#comment-11210</link>
		<dc:creator>Microsoft&#8217;s Mojave Experiment Exposes Serious Vista Problems &#8212; RoughlyDrafted Magazine</dc:creator>
		<pubDate>Fri, 15 Aug 2008 08:28:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.roughlydrafted.com/2007/12/20/vista-vs-mac-os-x-security-why-george-ous-zdnet-vulnerability-numerology-is-absurd/#comment-11210</guid>
		<description>[...] Vista vs Mac OS X Security: Why George Ou’s ZDNet Vulnerability Numerology is Absurd [...]</description>
		<content:encoded><![CDATA[<p>[...] Vista vs Mac OS X Security: Why George Ou’s ZDNet Vulnerability Numerology is Absurd [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: AppleMania.info » Numerologia da vulnerabilidade de George Ou é absurda, diz especialista</title>
		<link>http://www.roughlydrafted.com/2007/12/21/vista-vs-mac-os-x-security-why-george-ous-zdnet-vulnerability-numerology-is-absurd/comment-page-1/#comment-10303</link>
		<dc:creator>AppleMania.info » Numerologia da vulnerabilidade de George Ou é absurda, diz especialista</dc:creator>
		<pubDate>Fri, 04 Jul 2008 11:27:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.roughlydrafted.com/2007/12/20/vista-vs-mac-os-x-security-why-george-ous-zdnet-vulnerability-numerology-is-absurd/#comment-10303</guid>
		<description>[...] detalhes no extenso e altamente recomendável artigo completo de [...]</description>
		<content:encoded><![CDATA[<p>[...] detalhes no extenso e altamente recomendável artigo completo de [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CanSecWest and Swiss Federal Institute of Tech Deliver Attacks on the Reality of Mac Security &#8212; RoughlyDrafted Magazine</title>
		<link>http://www.roughlydrafted.com/2007/12/21/vista-vs-mac-os-x-security-why-george-ous-zdnet-vulnerability-numerology-is-absurd/comment-page-1/#comment-6616</link>
		<dc:creator>CanSecWest and Swiss Federal Institute of Tech Deliver Attacks on the Reality of Mac Security &#8212; RoughlyDrafted Magazine</dc:creator>
		<pubDate>Fri, 28 Mar 2008 14:06:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.roughlydrafted.com/2007/12/20/vista-vs-mac-os-x-security-why-george-ous-zdnet-vulnerability-numerology-is-absurd/#comment-6616</guid>
		<description>[...] Vista vs Mac OS X Security: Why George Ou’s ZDNet Vulnerability Numerology is Absurd security.itworld.com - Microsoft vs. Apple: Who patches 0-days faster? PdfMeNot.com - 0-Day Patch Study  Why the Swiss Study was Fatally Flawed. The main tipoff that the study was completely worthless is that it neatly compares “0-day” patches across unrelated platforms. Three main points below describe specifically why this is inherently flawed. As an introduction: a 0-day patch is one delivered the same day the exploitable flaw that it corrects becomes publicly disclosed. [...]</description>
		<content:encoded><![CDATA[<p>[...] Vista vs Mac OS X Security: Why George Ou’s ZDNet Vulnerability Numerology is Absurd security.itworld.com &#8211; Microsoft vs. Apple: Who patches 0-days faster? PdfMeNot.com &#8211; 0-Day Patch Study  Why the Swiss Study was Fatally Flawed. The main tipoff that the study was completely worthless is that it neatly compares “0-day” patches across unrelated platforms. Three main points below describe specifically why this is inherently flawed. As an introduction: a 0-day patch is one delivered the same day the exploitable flaw that it corrects becomes publicly disclosed. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom Krazit of CNET and Eric Savitz of Barrons Deny the Jesus Phone &#8212; RoughlyDrafted Magazine</title>
		<link>http://www.roughlydrafted.com/2007/12/21/vista-vs-mac-os-x-security-why-george-ous-zdnet-vulnerability-numerology-is-absurd/comment-page-1/#comment-4491</link>
		<dc:creator>Tom Krazit of CNET and Eric Savitz of Barrons Deny the Jesus Phone &#8212; RoughlyDrafted Magazine</dc:creator>
		<pubDate>Sat, 26 Jan 2008 10:38:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.roughlydrafted.com/2007/12/20/vista-vs-mac-os-x-security-why-george-ous-zdnet-vulnerability-numerology-is-absurd/#comment-4491</guid>
		<description>[...] The iTunes Monopoly/Failure Myth Who Was the Biggest Loser at Macworld? Vista vs Mac OS X Security: Why George Ou’s ZDNet Vulnerability Numerology is Absurd [...]</description>
		<content:encoded><![CDATA[<p>[...] The iTunes Monopoly/Failure Myth Who Was the Biggest Loser at Macworld? Vista vs Mac OS X Security: Why George Ou’s ZDNet Vulnerability Numerology is Absurd [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bill</title>
		<link>http://www.roughlydrafted.com/2007/12/21/vista-vs-mac-os-x-security-why-george-ous-zdnet-vulnerability-numerology-is-absurd/comment-page-1/#comment-3898</link>
		<dc:creator>Bill</dc:creator>
		<pubDate>Thu, 10 Jan 2008 13:20:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.roughlydrafted.com/2007/12/20/vista-vs-mac-os-x-security-why-george-ous-zdnet-vulnerability-numerology-is-absurd/#comment-3898</guid>
		<description>Actually Jabberwolf, You are both rude and stupid. If you can read above or at least know a little about statistics and valid data collection and evaluations, then you would understand that the assertions are invalid. Besides the fact that the Secunia doesn&#039;t even find most of the data, only reports what they find, even when wrong, causing them to retract it when challenged. And the fact that the compilation was made by Mac bashers like yourself, who lack any credibility. Yes Jabbiemouth, you are the stupid idiot.
 Windows girls go to Mac sites to badger, when Mac fans go to Windows sites to defend  the Mac bashing. It so sad that you fools can leave us alone. If the market share is as low as you say, they why not ignore us? Oh yeh, you are all rude and stupid. Good luck with the Zillion viruses, trojans, and malware. I hope that opur 3 to 5 programs to try and prevent or eliminate them works. Talk about insecure! It&#039;s Windows and winfans! Just to let you know, 4 friends with completely disabled Windows XP computers had over a total of 600 viruses and more malware and trojan horses. It&#039;s real, unlike the crap that was published by Ou and company from an incompetent company that tries to prove it&#039;s existence by listing wrongware [Secunia]. Secunia should be sued for fraud. One other thing dumbass, if you checked, most of the Apple data was from OS 10.3, which was 2 operating systems ago, and of course all patched. Microsoft, just doesn&#039;t care to tell you how insecure Windows is, but the real tally of sucessful exploitations is the fact [you stupid butthead]</description>
		<content:encoded><![CDATA[<p>Actually Jabberwolf, You are both rude and stupid. If you can read above or at least know a little about statistics and valid data collection and evaluations, then you would understand that the assertions are invalid. Besides the fact that the Secunia doesn&#8217;t even find most of the data, only reports what they find, even when wrong, causing them to retract it when challenged. And the fact that the compilation was made by Mac bashers like yourself, who lack any credibility. Yes Jabbiemouth, you are the stupid idiot.<br />
 Windows girls go to Mac sites to badger, when Mac fans go to Windows sites to defend  the Mac bashing. It so sad that you fools can leave us alone. If the market share is as low as you say, they why not ignore us? Oh yeh, you are all rude and stupid. Good luck with the Zillion viruses, trojans, and malware. I hope that opur 3 to 5 programs to try and prevent or eliminate them works. Talk about insecure! It&#8217;s Windows and winfans! Just to let you know, 4 friends with completely disabled Windows XP computers had over a total of 600 viruses and more malware and trojan horses. It&#8217;s real, unlike the crap that was published by Ou and company from an incompetent company that tries to prove it&#8217;s existence by listing wrongware [Secunia]. Secunia should be sued for fraud. One other thing dumbass, if you checked, most of the Apple data was from OS 10.3, which was 2 operating systems ago, and of course all patched. Microsoft, just doesn&#8217;t care to tell you how insecure Windows is, but the real tally of sucessful exploitations is the fact [you stupid butthead]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jabberwolf</title>
		<link>http://www.roughlydrafted.com/2007/12/21/vista-vs-mac-os-x-security-why-george-ous-zdnet-vulnerability-numerology-is-absurd/comment-page-1/#comment-3894</link>
		<dc:creator>jabberwolf</dc:creator>
		<pubDate>Thu, 10 Jan 2008 04:25:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.roughlydrafted.com/2007/12/20/vista-vs-mac-os-x-security-why-george-ous-zdnet-vulnerability-numerology-is-absurd/#comment-3894</guid>
		<description>So?

Your ENTIRE article tries to make excuses for about 1/3 of the holes. That still leaves OSX with about 10 times the security breaches!!!

Its kinda sad then mactards cant face the truth!
But it only shows how pathetic they can be when faced with facts.... excuses excuses.

Thats the difference, Windows users arent fans, we dont make excuses, we just want a fix, not an excuse.

Someone said why OSX doesnt get many viruses. Just based on the market share they wont spread a virus as fast, nor will it actually make it to many of its users.

Simple math mactards lack, exponential versus linear spread. Macs are more linear contact by numbers, MS users more exponential.</description>
		<content:encoded><![CDATA[<p>So?</p>
<p>Your ENTIRE article tries to make excuses for about 1/3 of the holes. That still leaves OSX with about 10 times the security breaches!!!</p>
<p>Its kinda sad then mactards cant face the truth!<br />
But it only shows how pathetic they can be when faced with facts&#8230;. excuses excuses.</p>
<p>Thats the difference, Windows users arent fans, we dont make excuses, we just want a fix, not an excuse.</p>
<p>Someone said why OSX doesnt get many viruses. Just based on the market share they wont spread a virus as fast, nor will it actually make it to many of its users.</p>
<p>Simple math mactards lack, exponential versus linear spread. Macs are more linear contact by numbers, MS users more exponential.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: lilgto64</title>
		<link>http://www.roughlydrafted.com/2007/12/21/vista-vs-mac-os-x-security-why-george-ous-zdnet-vulnerability-numerology-is-absurd/comment-page-1/#comment-3830</link>
		<dc:creator>lilgto64</dc:creator>
		<pubDate>Fri, 04 Jan 2008 14:12:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.roughlydrafted.com/2007/12/20/vista-vs-mac-os-x-security-why-george-ous-zdnet-vulnerability-numerology-is-absurd/#comment-3830</guid>
		<description>I think Mark Twain said it best: 

&quot;There are three kinds of lies: lies, damned lies and statistics.&quot; 

source: http://www.twainquotes.com/Statistics.html</description>
		<content:encoded><![CDATA[<p>I think Mark Twain said it best: </p>
<p>&#8220;There are three kinds of lies: lies, damned lies and statistics.&#8221; </p>
<p>source: <a href="http://www.twainquotes.com/Statistics.html" rel="nofollow">http://www.twainquotes.com/Statistics.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: avocade</title>
		<link>http://www.roughlydrafted.com/2007/12/21/vista-vs-mac-os-x-security-why-george-ous-zdnet-vulnerability-numerology-is-absurd/comment-page-1/#comment-3077</link>
		<dc:creator>avocade</dc:creator>
		<pubDate>Mon, 24 Dec 2007 13:43:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.roughlydrafted.com/2007/12/20/vista-vs-mac-os-x-security-why-george-ous-zdnet-vulnerability-numerology-is-absurd/#comment-3077</guid>
		<description>Fraud is a big word. Agree about the general sentiment of the article, however.</description>
		<content:encoded><![CDATA[<p>Fraud is a big word. Agree about the general sentiment of the article, however.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: danieleran</title>
		<link>http://www.roughlydrafted.com/2007/12/21/vista-vs-mac-os-x-security-why-george-ous-zdnet-vulnerability-numerology-is-absurd/comment-page-1/#comment-2979</link>
		<dc:creator>danieleran</dc:creator>
		<pubDate>Sun, 23 Dec 2007 02:57:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.roughlydrafted.com/2007/12/20/vista-vs-mac-os-x-security-why-george-ous-zdnet-vulnerability-numerology-is-absurd/#comment-2979</guid>
		<description>[This article was posted to slashdot and received some interesting comments there]

http://it.slashdot.org/comments.pl?sid=396432&amp;cid=21780042

Is Secunia presenting slanted information with the expectation it will be misused?

Here&#039;s one even better: We use GeSHi [qbnz.com] (Generic Syntax Highlighter) in WikkaWiki [wikkawiki.org]. We often scour the so-called &quot;security vulnerability&quot; databases because we&#039;ve found many inaccuracies. In this specific case, Secunia issued this statement:

&gt; we noticed the following entry in the changelog for GeSHi 1.0.7.18 and
&gt; are about to issue an advisory based on this information.
&gt;
&gt; &quot;Committed security fix for htmlspecialchars vulnerability. Also makes
&gt; supporting multiple languages a lot easier&quot;
&gt; http://sourceforge.net/project/shownotes.php?release_id=489035 [sourceforge.net]
&gt;
&gt; To serve our mutual customers best we would appreciate to receive your
&gt; comments on this issue before we publish our advisory.


WTF? This was a vulnerability in PHP&#039;s htmlspecialchars() function, NOT GeSHi. Yet, Secunia was planning on milking this vulnerability in order to boost its &quot;vulnerability count&quot; at the expense of a project that had absolutely NOTHING to do with the vulnerability.

You see, these so-called &quot;vulnerability experts&quot; try to wring out as many vulnerabilities as possible, because we all know that the most effective &quot;vulnerability expert&quot; will be the one with the most posted vulnerabilities. So they go on fishing expeditions to uncover vulnerabilities that really don&#039;t exist.

Or an even worse practice: &quot;bottom-fishing&quot; changelogs and bug trackers in order to discover vulnerabilities that have already been addressed. Here&#039;s another instance where Secunia was caught trying to boost its street cred through disingenuous reporting: They apparently scoured our bug tracking database and discovered an issue (already fixed!) and falsely implied in their report that the content of wiki pages marked private might be accessible via RSS. This was clearly false, as the original bug report indicated that the page name (not content) could be accessed. Secunia later corrected [secunia.com] the false report.

We&#039;ve caught Secunia doing this on several occasions. My advice to anyone who is involved in an OSS project is to regularly scour the vulnerability databases and challenge each and every advisory that you believe is not accurate. You might be surprised at the amount of so-called &quot;vulnerability intelligence&quot; out there that is blatantly false, outdated, or inaccurate.</description>
		<content:encoded><![CDATA[<p>[This article was posted to slashdot and received some interesting comments there]</p>
<p><a href="http://it.slashdot.org/comments.pl?sid=396432&#038;cid=21780042" rel="nofollow">http://it.slashdot.org/comments.pl?sid=396432&#038;cid=21780042</a></p>
<p>Is Secunia presenting slanted information with the expectation it will be misused?</p>
<p>Here&#8217;s one even better: We use GeSHi [qbnz.com] (Generic Syntax Highlighter) in WikkaWiki [wikkawiki.org]. We often scour the so-called &#8220;security vulnerability&#8221; databases because we&#8217;ve found many inaccuracies. In this specific case, Secunia issued this statement:</p>
<p>> we noticed the following entry in the changelog for GeSHi 1.0.7.18 and<br />
> are about to issue an advisory based on this information.<br />
><br />
> &#8220;Committed security fix for htmlspecialchars vulnerability. Also makes<br />
> supporting multiple languages a lot easier&#8221;<br />
> <a href="http://sourceforge.net/project/shownotes.php?release_id=489035" rel="nofollow">http://sourceforge.net/project/shownotes.php?release_id=489035</a> [sourceforge.net]<br />
><br />
> To serve our mutual customers best we would appreciate to receive your<br />
> comments on this issue before we publish our advisory.</p>
<p>WTF? This was a vulnerability in PHP&#8217;s htmlspecialchars() function, NOT GeSHi. Yet, Secunia was planning on milking this vulnerability in order to boost its &#8220;vulnerability count&#8221; at the expense of a project that had absolutely NOTHING to do with the vulnerability.</p>
<p>You see, these so-called &#8220;vulnerability experts&#8221; try to wring out as many vulnerabilities as possible, because we all know that the most effective &#8220;vulnerability expert&#8221; will be the one with the most posted vulnerabilities. So they go on fishing expeditions to uncover vulnerabilities that really don&#8217;t exist.</p>
<p>Or an even worse practice: &#8220;bottom-fishing&#8221; changelogs and bug trackers in order to discover vulnerabilities that have already been addressed. Here&#8217;s another instance where Secunia was caught trying to boost its street cred through disingenuous reporting: They apparently scoured our bug tracking database and discovered an issue (already fixed!) and falsely implied in their report that the content of wiki pages marked private might be accessible via RSS. This was clearly false, as the original bug report indicated that the page name (not content) could be accessed. Secunia later corrected [secunia.com] the false report.</p>
<p>We&#8217;ve caught Secunia doing this on several occasions. My advice to anyone who is involved in an OSS project is to regularly scour the vulnerability databases and challenge each and every advisory that you believe is not accurate. You might be surprised at the amount of so-called &#8220;vulnerability intelligence&#8221; out there that is blatantly false, outdated, or inaccurate.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

