2 ms·
"CVE counting" is not necessarily a good proxy for "security". The practice of drawing conclusions from various CVE statistics has been variously debunked over
by scarybeast 10y ago
"CVE counting" is not necessarily a good proxy for "security". The practice of drawing conclusions from various CVE statistics has been variously debunked over the years. I strongly recommend reading this 6-year old(!) resource from @lcamtuf:
https://lcamtuf.blogspot.com/2010/05/vulnerability-databases-and-pie-charts.html https://lcamtuf.blogspot.com/2010/05/vulnerability-databases...
My own personal favorite anecdotes of why CVE counting is fail:
1) Adobe used to tour around presenting a chart of how their CVEs were decreasing over time. But then @taviso did a bit of simple fuzzing and found almost 100 issues. So it turns out the Adobe CVE count was low simply because no-one was looking hard. In fact, Adobe assigned a single CVE to all the issues, in this waffling blog post:
http://blogs.adobe.com/security/2011/08/how-did-you-get-to-that-number.html http://blogs.adobe.com/security/2011/08/how-did-you-get-to-t...
2) Google Chrome has lots of CVEs because of the monetary incentives to go and find and report them. A quick comparison of CVEs for Chrome vs. some browser without a decent rewards program might lead you to incorrect conclusions.
3) Historically, Microsoft did not publicly disclosure or assign CVEs for issues found internally by employees. This contrasts with Chrome and Firefox, which have a greater culture of openness, where internal security discoveries are documented publicly. Quasi-arbitrary decisions like this bend the numbers all over the place, from vendor to vendor and product to product.