The following extract from an article by Microsoft mentions Linux, which isa 
version of Unix, as having "security vulnerabilities". Does this mean that 
System X, which has at its core the BSD version of Unix, will become a target 
for viruses, ending the virtually virus-free Mac environment?

Note: I don't regard Micro$oft software as part of the virus-free Mac 
environment.

Here follows part of Micro$oft's article:

It's Time to End Information Anarchy

By Scott Culp
October 2001

Code Red. Lion. Sadmind. Ramen. Nimda. In the past year, computer worms with 
these names have attacked computer networks around the world, causing billions 
of dollars of damage. They paralysed computer networks, destroyed data, and in 
some cases left infected computers vulnerable to future attacks. The people who 
wrote them have been rightly condemned as criminals. But they needed help to 
devastate our networks. And we in the security community gave it to them.

It's high time the security community stopped providing blueprints for building 
these weapons. And it's high time computer users insisted that the security 
community live up to its obligation to protect them. We can and should discuss 
security vulnerabilities, but we should be smart, prudent, and responsible in 
the way we do it.

Arming the enemy

First, let's state the obvious. All of these worms made use of security flaws 
in the systems they attacked, and if there hadn't been security vulnerabilities 
in Windows®, Linux, and Solaris, none of them could have been written. This is 
a true statement, but it doesn't bring us any closer to a solution. While the 
industry can and should deliver more secure products, it'sunrealistic to expect 
that we will ever achieve perfection. All non-trivial software contains bugs, 
and modern software systems are anything but trivial. Indeed, they are among 
the most complex things humanity has ever developed. Security vulnerabilities 
are here to stay.

If we can't eliminate all security vulnerabilities, then it becomes all themore 
critical that we handle them carefully and responsibly when they're found. Yet 
much of the security community handles them in a way that fairly guarantees 
their use, by following a practice that's best described as information 
anarchy. This is the practice of deliberately publishing explicit, step-by-step 
instructions for exploiting security vulnerabilities, without regard for how 
the information may be used.

The relationship between information anarchy and the recent spate of worms is 
undeniable. Every one of these worms exploited vulnerabilities for 
whichstep-by-step exploit instructions had been widely published. But the 
evidence is more far conclusive than that. Not only do the worms exploit the 
same vulnerabilities, they do so using the same techniques as were published 
-in some cases even going so far as to use the same file names and identical 
exploit code. This is not a coincidence. Clearly, the publication of exploit 
details about the vulnerabilities contributed to their use as weapons.
-- 
Regards,

Ray Forma
50 Harvest Road, North Fremantle WA 6159, Australia
Tel & Fax 61 (0)8 9335 6568