/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Flaw counting comparisons useful but fall short of true picture

The Windows vs Linux security report card that I wrote about from TechEd two weeks ago is officially out and Microsoft has stepped up its PR campaign to argue that Windows Vista has a "lower vulnerability fix and disclosure rate" than competitive Linux distributions.

Zero Day Ryan Naraine

Context & Ripple Effects

Two weeks after Zero Day asked how Windows Vista really rates ahead of TechEd, Microsoft has made its answer official: a six-month vulnerability report card, published via Jeff Jones's blog and pushed through a coordinated PR campaign claiming Vista has a lower vulnerability fix and disclosure rate than competing Linux distributions.

The pickup was broad — eWEEK framed it as 'Vista more secure than Linux, Mac OS X' — but this column's verdict is that flaw counting, however useful, falls short of a true security picture. That tension between Microsoft's numbers and what the numbers can actually prove is the real story.

First-order effects

  • Enterprise buyers evaluating Vista against Linux distributions now have a Microsoft-authored dataset in hand, shifting the comparison from anecdote to contested statistics.
  • Linux distributors are put on the defensive, forced to argue methodology — severity weighting, disclosure practices, unpatched flaws — rather than accept raw fix counts as the scoreboard.

Second-order effects

  • Rival vendors and independent researchers gain an incentive to publish their own counter-scorecards using different methodologies, turning OS security measurement into a recurring marketing battleground.
  • Security metrics become procurement ammunition: whoever controls the counting convention — vulnerabilities per month, days-to-fix, or severity-adjusted totals — gains leverage in enterprise platform decisions.

Third-order effects

  • If vendor-published flaw-count scorecards become standard evidence in platform selection, vendors will be rewarded for optimizing disclosure and patch-rate optics, a metric that may diverge from actual exploit resistance — pushing the industry toward third-party verification of any such report card.

The trend: Operating system security is being argued through quantified, vendor-commissioned scorecards rather than incident history, making the methodology behind the count as contested as the count itself.