Was Mac OS X really the most vulnerable in 2015?
blog.malwarebytes.org
blog.malwarebytes.org
The goal of CVEs is not to point fingers to companies and compile statistics based on ownernship. I don't see any value or helpful outcome from these these "research" security firms (and the tech blogs) treating it like such and creating FUD.
“This tells us more clearly about the severity of the vulnerabilities in the data, which is a more important metric than just how many total vulnerabilities there are.”
And if you even ignore type of product, then Adobe goes first, but this has no impact on "which OS was the most vulnerable".
If, for example, researchers found 10k vulnerabilities in windows 3.1, it wouldn't make sense to ding microsoft for an insecure operating system, because no one runs that and it's not reasonable to expect support.
I would not be overly surprised if it turned out somebody was still using Windows 3.1 - I know of at least one company still running NT 4 on at least a few select machines. (This does not invalidate your point, though.)
Firstly the data aren't usable for this kind of analysis even if you bucket them differently: https://www.cvedetails.com/how-does-it-work.php
Secondly, we know nothing about exposure, because we don't know how the relative levels of attention or how quickly the vulnerabilities are patched.
A high discovery rate is as indicative of the attention given to the platform as it is to the underlying number of vulnerabilities. A high discovery rate plus relatively high rate of distribution of patches could means a system is less vulnerable.
I'm not saying this is the case - just that the data presented are simply useless for ranking software vulnerability levels.
For what it's worth, in baseball, a foul ball or grounding into an out do not count as hits; a hit means a batter successfully reached first base without a fielder's choice. Number of hits is still not very meaningful — something like slugging, on-base percentage, or OPS is more instructive — but it's not as bad as this example is making out.
but this article is critcal of the FUD that is being spread from poorly drawn conclusions about CVE statistics. they're not trying to sell you anything.
http://www.imore.com/os-x-and-ios-security-vulnerabilities-a...