Debian has the most vulnerabilities according to report
#1
Debian has the most vulnerabilities according to report
https://www.techradar.com/news/windows-1...ally-linux

Ignoring the editorialized title, this is apparently true for the last decade. Windows 7 and 10 have less vulnerabilities combined compared to Debian, and on their own, less than Android, Ubuntu etc.

I'm not surprised, though I do think that Linux vulnerabilities can be mitigated to a point especially if you believe apparmor and such can protect you.

I'm the system admin of this site. Private security technician, licensed locksmith, hack of a c developer and vintage computer enthusiast. 

https://contrib.irixnet.org/raion/ -- contributions and pieces that I'm working on currently. 

https://codeberg.org/SolusRaion -- Code repos I control

Technical problems should be sent my way.
Raion
Chief IRIX Officer

Trade Count: (9)
Posts: 4,239
Threads: 533
Joined: Nov 2017
Location: Eastern Virginia
Website Find Reply
03-10-2020, 02:33 AM
#2
RE: Debian has the most vulnerabilities according to report
I use Debian (Devuan, same thing but without systemd). I've been looking into something like Slackware but Debian is just too convenient to leave. I kinda wonder if more vulnerabilities are being found because more eyes are on it or if things are just that poorly configured and maintained.

Octane2  R14k 600MHz, V10, 2GB RAM, 73GB disk, IRIX 6.5.22
shrek
It's not done until it's ogre.

Trade Count: (0)
Posts: 233
Threads: 19
Joined: Jan 2019
Location: United States
Find Reply
03-10-2020, 10:51 AM
#3
RE: Debian has the most vulnerabilities according to report
This is the sort of fodder where everybody can find some 'facts' to support their own opinion.

So what if Windows 10 suffered 1111 vulnerabilities in the last 20 years, you might as well say it had 1111 in the last 200 years because it was introduced only 4 years ago. Debian actually existed 20 years ago and had 3067? I'll let you do the math. Then again, who even cares about 20 years ago? Impact of vulnerabilities or response time not taken into account. How many were in the 'base installation' vs. the god-knows-how-many thousand in 'contrib' that few people use, etc etc.

Pffft.
jan-jaap
SGI Collector

Trade Count: (0)
Posts: 1,048
Threads: 37
Joined: Jun 2018
Location: Netherlands
Website Find Reply
03-10-2020, 11:30 AM
#4
RE: Debian has the most vulnerabilities according to report
Jan, they apparently we're talking about for the last 10 years and combining Windows 7 and 10.

Read the actual article. Nobody's spreading FUD or lies. It's just information nested in editorialism. Editorialism is bad, but what are we gonna do?

I'm the system admin of this site. Private security technician, licensed locksmith, hack of a c developer and vintage computer enthusiast. 

https://contrib.irixnet.org/raion/ -- contributions and pieces that I'm working on currently. 

https://codeberg.org/SolusRaion -- Code repos I control

Technical problems should be sent my way.
Raion
Chief IRIX Officer

Trade Count: (9)
Posts: 4,239
Threads: 533
Joined: Nov 2017
Location: Eastern Virginia
Website Find Reply
03-10-2020, 04:56 PM
#5
RE: Debian has the most vulnerabilities according to report
I only skimmed the article, but it doesn't seem to make clear that "in Debian" can include add-on software such as Apache, MySQL, PHP, OpenSSL, etc.  If the Debian numbers do include those and all the other packages in the Debian repositories, then they are actually surprisingly low.  I doubt the Windows figures include any add-ons so I really hope they weren't included for Debian.  That would be very unfair.  But I can't see anything in the article that makes it clear one way or the other.

SGI:  Indigo, Indigo2, Octane, Origin 300
Sun:  SPARCstation 20 (x4), Ultra 2, Blade 2500, T5240
HP:  9000/380, 425e, C8000
Digital: DECstation 5000/125, PWS 600au
jpstewart
Developer

Trade Count: (1)
Posts: 444
Threads: 6
Joined: May 2018
Location: SW Ontario, CA
Find Reply
03-10-2020, 07:28 PM
#6
RE: Debian has the most vulnerabilities according to report
I would imagine it's either one of two things:

Either a debian base install

or Debian's repo as a whole. Unfortunately their methodology is muddled.

I'm the system admin of this site. Private security technician, licensed locksmith, hack of a c developer and vintage computer enthusiast. 

https://contrib.irixnet.org/raion/ -- contributions and pieces that I'm working on currently. 

https://codeberg.org/SolusRaion -- Code repos I control

Technical problems should be sent my way.
Raion
Chief IRIX Officer

Trade Count: (9)
Posts: 4,239
Threads: 533
Joined: Nov 2017
Location: Eastern Virginia
Website Find Reply
03-10-2020, 08:27 PM


Forum Jump:


Users browsing this thread: 1 Guest(s)