Welcome | Sign In
CRMBuyer.com
Applications

Bug Ferret Gives Linux High Grades

Print Version
E-Mail Article
Reprints
Bug Ferret Gives Linux High Grades

The Coverity analysis is sure to throw kerosene on the heated debate over the security merits of Linux over Windows. Asked if Coverity's data showed that Linux was less prone to security vulnerabilities than Microsoft's operating system, CEO Seth Hallem replied, "Our analysis does not indicate that."


Reading the Avaya-Nortel Roadmap requires a navigator
The release of the Avaya-Nortel roadmap has many people wondering what lies ahead for their customer contact initiatives. Join Ovum’s Ian Jacobs and Aspect CTO Gary Barnett to discuss how the integration of two product lines may affect you. Register for the webinar.

A company that makes a tool for finding bugs in software code disclosed this week that the Linux kernel is far less flawed than many programs people pay money for.

According to San Francisco-based Coverity, its source-code auditing tool found the Linux 2.6 kernel had 985 bugs in its 5.7 million lines of code. The typical commercial software program averages bug densities from 10 to 20 flaws per 1000 lines of code, explained Coverity CEO Seth Hallem.

He maintained that there is a relationship between how buggy a program is and how secure it is from hacker attacks. "Almost any bug that can be triggered by a user from the outside -- and, honestly, almost every bug can -- is a security vulnerability," Hallem told LinuxInsider.

Click here for LiveOps

Linux Versus Windows Security

"To say that there are less bugs in Linux code than there are in your average commercial software means that Linux has a higher level of security because there are fewer of these latent problems that a user from the outside could potentially trigger," he said.

The Coverity analysis is sure to throw kerosene on the heated debate over the security merits of Linux over Windows. Asked if Coverity's data showed that Linux was less prone to security vulnerabilities than Microsoft's (Nasdaq: MSFT) operating system, Hallem replied, "Our analysis does not indicate that."

He added that he could not say that Linux is more secure than Windows without running Microsoft's code through Coverity's audit tool. "Because of the closed source arrangement that Microsoft has, I can't see that source code," he said.

More Attacks on Windows

A Microsoft spokesperson, who requested anonymity, noted to LinuxInsider via e-mail: "Microsoft respects the work done by Coverity but cannot support the validity of the test results until we can conduct further investigation of the methodologies and variables involved in the testing process."

"It is important to note that Coverity's research did not analyze Windows and Windows was not a part of their bug comparison," the spokesperson added.

"My feeling is that we really don't know if one operating system is more secure than another," Jeffrey Wade, Linux marketing communication manager at HP (NYSE: HPQ) in Palo Alto, California, said.

He pointed out that Windows is the focus of attacks more frequently than any other operating system. "It stands to reason that we're going to see more issues there because that's where the focus is," he reasoned. "If we saw that same intensity of focus on Linux, we'd see issues and problems there as well."

People Problem

Whether one operating system is inherently more secure than another can be a misleading measure to users, according to Laura DiDio, senior analyst for the Yankee Group in Boston. "Software, no matter how secure you make it, is only going to be as secure or good as the people who are configuring it, managing it and deploying it," she said.

While security is important, Wade observed, its influence on buyers appears to be marginal. "We support multiple operating systems as a strategy for our company," he said. "By and large, security is not discouraging customers from deploying solutions on one operating system over another."

Hallem observed that the Linux kernel is vastly improved from four years ago when he and his colleagues began developing their tool for auditing flaws in source code. "Our tool was much more primitive at that time and the Linux code base was much earlier in its development and smaller, but we still found defect densities eight times what they are now," he explained.

Wade added: "The maturity of the folks contributing to Linux now is very high. And the development community over the last several years have employed practices and procedures that are making the development process much more mature than it has been."


Print Version E-Mail Article Reprints More by John P. Mello Jr.


More by John P. Mello Jr.

FileMaker Pro Goes to 11
March 15, 2010
FileMaker has pushed out the 11th version of its Pro database product, and its new charting capabilities top the list of new features. Pie, bar and area charts can be created instantly and will change dynamically as the data underlying them changes. In addition, FileMaker 11 includes more than 30 "Start Solutions" that address the kind of real-world information needs for which business people buy a database.
Corel's X3 Photo Editor Paints a Pretty Picture
March 11, 2010
Corel has packed its latest version of PaintShop Photo Pro, X3, with a boatload of new features, many of which are aimed at smoothing out the photographer's workflow. It's tied in a new batch processing feature as well as Express Lab, which gives photo editors the power of combined tools. There's also better support for RAW files and a bonus Painter Photo Essentials 4 app for adding an artistic flourish.
Aperture's Makeover Delights Photogs
March 08, 2010
While Aperture's new features make it more attractive than ever to professional photographers, its main selling point appears to be its superior ability to automate a photographer's workflow. "For me, the most important thing about Aperture -- always has been and remains -- is that it is simply the most powerful archiving tool available," said photographer Bill Frakes.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network