3 ms·
That's extremely vague. The CVE database is a spectacularly terrible thing to use to try and assess comparative "security" because there are so so many things s
by ris 3y ago
That's extremely vague. The CVE database is a spectacularly terrible thing to use to try and assess comparative "security" because there are so so many things social, organizational and cultural that affect whether and how an issue gets discovered, reported (or hushed up), appropriately scored (almost a nonsense in itself), or has interaction with other components taken into account. For instance it is 100% routine to register any buffer overflow as a CVE, even cases which will always be stopped by compiler hardening flags or OS hardening features.
This sort of citation or "research" is not remotely what the CVE database is for.
- pjmlp 3y agoIt is what it is. I am not playing the citation game, already have enough of it during Usenet and not feeling bored enough today.
- zare_st 3y agoThen don't put an irrelevant citation if you don't want to play the game. One is peer reviewed, another isn't, so it's like comparing results from a self-reported against an academically measured study. The availability of Windows source for partners is nothing compared to how many educated eyes are on the Linux source at a given moment. Of course none of this matters because the BSDs are more secure than both but they wouldn't pick them over Windows IRL anyways. Why Windows are preferred is a matter of business and not technology. This is a long topic and if you were in Usenet advocacies you know what it's all about. Support, logistics, number of trained people in the market, certifications, so on and so forth. Linux doesn't have an easy fight there.