DrZeuss meldt: dat ze bij Security focus een paar mooie tabellen en grafieken hebben gemaakt waar we kunnen zien hoeveel security holes er per OS gevonden worden. Een nuttige conlusie kan je hier niet aan verbinden (behalve dan dat er elk jaar een groter aantal lekken worden gevonden), maar statistieken zijn toch altijd leuk (de DPC hitparade bewijst dat ):
The following are statistics compiled from the data in the BUGTRAQ Vulnerability Database. The statistics should not be taken to imply that some particular operating system or application is more or less secure than another one. They are simply a count of how many vulnerabilities associated with each of them is in the database for these year.
The are many factors that should be considered while trying to interpret these numbers. The numbers do not distinguish between vulnerabilities discovered in the wild and those found proactively by developers or security researchers. Nor do they say anything about how quickly the vulnerabilities were fixed by the vendors. They do not take into accounts the popularity or impact of a vulnerability. A root shell vulnerability is treated the same as a disclosure of sensitive information.
Number of OS Vulnerabilities by Year OS 1997 1998 1999 2000Debian 2 2 29 5 FreeBSD 4 2 18 6 HP-UX 8 5 7 3 IRIX 26 13 8 3 Linux (aggr.) 10 23 84 30 MacOS 0 1 5 0 MacOS X Server 0 0 1 0 NetBSD 1 4 10 3 OpenBSD 1 2 4 2 RedHat 5 10 38 37 Solaris 24 31 34 6 Windows 3.1x/95/98 1 1 46 11 Windows NT 4 6 99 34