The following extract from an article by Microsoft mentions Linux, which isa version of Unix, as having "security vulnerabilities". Does this mean that System X, which has at its core the BSD version of Unix, will become a target for viruses, ending the virtually virus-free Mac environment?
Note: I don't regard Micro$oft software as part of the virus-free Mac environment. Here follows part of Micro$oft's article: It's Time to End Information Anarchy By Scott Culp October 2001 Code Red. Lion. Sadmind. Ramen. Nimda. In the past year, computer worms with these names have attacked computer networks around the world, causing billions of dollars of damage. They paralysed computer networks, destroyed data, and in some cases left infected computers vulnerable to future attacks. The people who wrote them have been rightly condemned as criminals. But they needed help to devastate our networks. And we in the security community gave it to them. It's high time the security community stopped providing blueprints for building these weapons. And it's high time computer users insisted that the security community live up to its obligation to protect them. We can and should discuss security vulnerabilities, but we should be smart, prudent, and responsible in the way we do it. Arming the enemy First, let's state the obvious. All of these worms made use of security flaws in the systems they attacked, and if there hadn't been security vulnerabilities in Windows®, Linux, and Solaris, none of them could have been written. This is a true statement, but it doesn't bring us any closer to a solution. While the industry can and should deliver more secure products, it'sunrealistic to expect that we will ever achieve perfection. All non-trivial software contains bugs, and modern software systems are anything but trivial. Indeed, they are among the most complex things humanity has ever developed. Security vulnerabilities are here to stay. If we can't eliminate all security vulnerabilities, then it becomes all themore critical that we handle them carefully and responsibly when they're found. Yet much of the security community handles them in a way that fairly guarantees their use, by following a practice that's best described as information anarchy. This is the practice of deliberately publishing explicit, step-by-step instructions for exploiting security vulnerabilities, without regard for how the information may be used. The relationship between information anarchy and the recent spate of worms is undeniable. Every one of these worms exploited vulnerabilities for whichstep-by-step exploit instructions had been widely published. But the evidence is more far conclusive than that. Not only do the worms exploit the same vulnerabilities, they do so using the same techniques as were published -in some cases even going so far as to use the same file names and identical exploit code. This is not a coincidence. Clearly, the publication of exploit details about the vulnerabilities contributed to their use as weapons. -- Regards, Ray Forma 50 Harvest Road, North Fremantle WA 6159, Australia Tel & Fax 61 (0)8 9335 6568

