Melanjutkan issue yang pernah saya lontarkan.. check hasil study.. ini..
http://securityportal.com/cover/coverstory20000117.html
Saya ambilkan bagian -bagiannya.
Red Hat did a better job of handling the "full disclosure" bug releases,
usually solving these problems in under 2 weeks, with 67 days being the
extreme case. Microsoft usually took over 3 weeks to patch "full
disclosure" bug releases, with a worst case of 146 days. Sun took in
excess of 100 days 3 times, including a mind-numbing 385 days for a CDE
problem related to a CERT advisory.
A frustrating part of "friendly" advisories is the fact that they are not
accompanied by any date history. If Bindview, for example, warns Microsoft
of a problem with NT, they do not provide the public any information about
how long the bug fix has been a "work in progress", and when they first
contacted Microsoft. This prevents us from gauging how efficiently the
vendor is solving problems stemming from "friendly" advisorie
If you assumed that most of the initial advisories came from industry
leading security firms with a staff of programmers and a fancy lab, you
would be wrong. In fact, a wide majority of the bugs are discovered by
individuals working independently. We think that this fact in itself is an
indirect nod to the power of Open Source - you never know where a bug or a
fix is going to come from and Open Source lets everyone participate in the
process.
What have we proven in compiling these numbers? We think an entire year
of data, while not conclusive, provides a fairly good indication that Open
Source software can have its security vulnerabilities identified and
repaired in a more timely manner than traditional closed source software.
A bug fix from Microsoft takes almost 50 percent longer to reach the
market as a fix from Red Hat - this despite the fact that Microsoft has
huge advantages in funding and employees. An attentive Linux administrator
Source seem to be providing Linux with the advantage needed to turn around
bug fixes so rapidly.
Is it possible that the slowness on the part of closed source vendors like
Microsoft is due in part to a different and more rigorous quality
assurance testing process? The process certainly is different, however
Microsoft had to re-release five of its security patches in 1999 due to
regression errors in the code, so it cannot likely be argued that the more
lengthy release cycles by closed source vendors is translating into higher
quality code.
===========================================================================
I Made Wiryana (0521-106 5328) Universitas Gunadarma - Indonesia
Rechnernetze und Verteilte Systeme http://nakula.rvs.uni-bielefeld.de/made
Universitaet Bielelfeld Check my e-zine :
[EMAIL PROTECTED] http://nakula.rvs.uni-bielefeld.de/majalah
===========================================================================
* Gunadarma Mailing List -----------------------------------------------
* Archives : http://milis-archives.gunadarma.ac.id
* Langganan : Kirim Email kosong ke [EMAIL PROTECTED]
* Berhenti : Kirim Email kosong ke [EMAIL PROTECTED]
* Administrator: [EMAIL PROTECTED]