DISCLAIMER: Este no es un post para Técnicos-Less.
Queridos todos y todas: el amigo Jeff Jones informa en su blog de CSO Online que publicará un ranking mensual sobre Vulnerabilidades de Sistemas Operativos.
Dicho Ranking tendrá diferentes secciones, una para workstations (Vista, Windows XP SP2, RHEL4 Workstation, Ubuntu 6.60 LTS, and Mac OS X) y otra para servers (Windows Server 2003, RHEL 4 AS, and Sun Solaris 10).
Pues bien queridos amigos, los resultados para lo que llevamos de este año 2007 (las estadísticas son de Enero y Febrero, aunque en el dibujito ponga Enero sólo), asombrosamente son los siguientes:

Imagen 1. Vulnerabilidades en sistemas operativos cliente.
Imagen 2. Vulnerabilidades en sistemas operativos servidor.Vale, ahora diréis que “Nivel de riesgo” no es lo mismo que “Número de vulnerabilidades”. Yo ya paso de discutir. La respuesta del amigo Jeff es esta:
“Security professionals will correctly note that vulnerabilities represent only
part of the security picture, with the risk equation also needing an
understanding of the potential threats and value of the information at risk.
However, number and quality of attackers are elements largely orthogonal to
factors that vendors have ability to influence. Vulnerabilities, on the other
hand, are a factor that vendors can influence directly by investing in process,
testing and other best practice Q&A techniques to reduce bugs and raise
quality of shipping products.”
Para más información, podéis leer el artículo de su blog “Exactly how biased am I?”, donde explica las diferencias entre Windows y Linux.
¿VOSOTROS QUE PENSÁIS?
Pues nada nada…..Ahí queda eso…
Buen finde!!
;)