Flaw counting comparisons useful but fall short of true picture
The Windows vs Linux security report card that I wrote about from TechEd two weeks ago is officially out and Microsoft has stepped up its PR campaign to argue that Windows Vista has a "lower vulnerability fix and disclosure rate" than competitive Linux distributions.
Context & Ripple Effects
Two weeks after Zero Day asked how Windows Vista really rates ahead of TechEd, Microsoft has made its answer official: a six-month vulnerability report card, published via Jeff Jones's blog and pushed through a coordinated PR campaign claiming Vista has a lower vulnerability fix and disclosure rate than competing Linux distributions.
The pickup was broad — eWEEK framed it as 'Vista more secure than Linux, Mac OS X' — but this column's verdict is that flaw counting, however useful, falls short of a true security picture. That tension between Microsoft's numbers and what the numbers can actually prove is the real story.
First-order effects
- Enterprise buyers evaluating Vista against Linux distributions now have a Microsoft-authored dataset in hand, shifting the comparison from anecdote to contested statistics.
- Linux distributors are put on the defensive, forced to argue methodology — severity weighting, disclosure practices, unpatched flaws — rather than accept raw fix counts as the scoreboard.
Second-order effects
- Rival vendors and independent researchers gain an incentive to publish their own counter-scorecards using different methodologies, turning OS security measurement into a recurring marketing battleground.
- Security metrics become procurement ammunition: whoever controls the counting convention — vulnerabilities per month, days-to-fix, or severity-adjusted totals — gains leverage in enterprise platform decisions.
Third-order effects
- If vendor-published flaw-count scorecards become standard evidence in platform selection, vendors will be rewarded for optimizing disclosure and patch-rate optics, a metric that may diverge from actual exploit resistance — pushing the industry toward third-party verification of any such report card.
The trend: Operating system security is being argued through quantified, vendor-commissioned scorecards rather than incident history, making the methodology behind the count as contested as the count itself.