{"id":199,"date":"2004-12-18T17:54:39","date_gmt":"2004-12-18T21:54:39","guid":{"rendered":""},"modified":"2006-05-21T18:47:24","modified_gmt":"2006-05-21T22:47:24","slug":"the_operating_system_oriented_security_d","status":"publish","type":"post","link":"https:\/\/fgiasson.com\/blog\/index.php\/2004\/12\/18\/the_operating_system_oriented_security_d\/","title":{"rendered":"The operating system oriented security debate is restarted."},"content":{"rendered":"<p><center><br \/>\n<strong>The operating system oriented security debate is restarted.<\/strong><br \/>\n<em>Please stop your child plays.<\/em><br \/>\n<\/center><\/p>\n<p>I read today <a href=\"http:\/\/www.wired.com\/news\/linux\/0,1411,66022,00.html\">an article on Wired News <\/a>that restart the debate on Linux versus other operating system security issues. The conclusion is:<\/p>\n<ol>\n<li>0.17 bugs per 1,000 lines of code in the Linux kernel<\/li>\n<li>20 to 30 bugs per 1,000 lines of code for commercial software<\/li>\n<\/ol>\n<p>These statistics have been collected by the Carnegie Mellon University&#8217;s <a href=\"http:\/\/www.cylab.cmu.edu\/\">CyLab <\/a>Sustainable Computing Consortium. The problem with these numbers is that they tell nothing. Fine, theoretically I have less chances that my Linux kernel had bugs that cause security threats. It&#8217;s sure that there are chances that the core (open source) of an OS was more studied than the softwares he runs. It&#8217;s exactly the present situation. <\/p>\n<p>What about all other things that come with all Linux distributions? Are they as studied as the Kernel? Let me doubts about it.<\/p>\n<p>What about the configuration? The complexity of an Operating System with all their services, applications and connectivity hardwares is not to forget. A program or a service can be well programmed; without any programming bugs; but only a bad configuration can lead to a security hole. You&#8217;ll tell me: Yes but the programming is perfect, without bugs then it&#8217;s impossible that such a thing append; if it happened then the cause is the user, not me, so it&#8217;s not mine. If you build a hell to configure system then yes it&#8217;s your problem. The interaction between a program and their plug-ins or a program with other programs can lead to unexpected behaviors. Usability is probably as important as programming practices.<\/p>\n<p>How can they resume computer security risks with lines of code? Is anyone can tell me this?<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The operating system oriented security debate is restarted. Please stop your child plays. I read today an article on Wired News that restart the debate on Linux versus other operating system security issues. The conclusion is: 0.17 bugs per 1,000 lines of code in the Linux kernel 20 to 30 bugs per 1,000 lines of [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[56],"tags":[],"class_list":["post-199","post","type-post","status-publish","format-standard","hentry","category-security"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/fgiasson.com\/blog\/index.php\/wp-json\/wp\/v2\/posts\/199","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fgiasson.com\/blog\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fgiasson.com\/blog\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fgiasson.com\/blog\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/fgiasson.com\/blog\/index.php\/wp-json\/wp\/v2\/comments?post=199"}],"version-history":[{"count":0,"href":"https:\/\/fgiasson.com\/blog\/index.php\/wp-json\/wp\/v2\/posts\/199\/revisions"}],"wp:attachment":[{"href":"https:\/\/fgiasson.com\/blog\/index.php\/wp-json\/wp\/v2\/media?parent=199"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fgiasson.com\/blog\/index.php\/wp-json\/wp\/v2\/categories?post=199"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fgiasson.com\/blog\/index.php\/wp-json\/wp\/v2\/tags?post=199"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}