Security bug lifetime
outflux.net
outflux.net
Over the same period, the kernel codebase grew from 8M LOC to 22M LOC. I'm not sure how to interpret this gap in security issues between the old "small" code vs the new massive code. Either kernel developers are a great deal more careful and the new code has a great deal fewer bugs, or we are about to get hit with a massive backlog of disclosures that bad guys are quietly piling up.
I believe most of that growth has been in the /drivers section of the kernel. While a driver can still root your kernel, the chance of one affecting you is much lower, unless it is one of the generic/common ones.
I don't understand where he's deducing the second sentence from.
I didn't really read the sentence that way though - it felt more like a clarification on why the number of vulnerabilities tend towards zero. Known vulnerabilities are few in number, but this doesn't mean it's vulnerability free.
This is what I would assume someone like the NSA does. They would have calculated a window of where it's most advantageous for them to find a bug and will then spend the resources at that time. Both in terms of bug life time and severity, but also user share.
This happened many times for both closed on open source projects. Not surprisingly, given how much is paid for a 0-day.
1. No matter how many eyeballs you put on a bug, it does not become more shallow
2. Each bug lives on average for 5 years
This makes it probable that whomever puts enough resources on researching for bugs discovers them _before_ the developers find it out: 5 years is a very long time in terms of security assessments. It is reasonable to assume there are actors with enough such resources - these aren't necessarily neither large, e.g. states, nor malicious. They could be, for instance, independent researchers aiming to improve the kernel. That's what makes it probable these flaws are likely known to malicious 3rd parties.
I doubt it, but it would be interesting to compare nontheless.
See this talk: https://www.youtube.com/watch?v=3Sx0uJGRQ4s
Windows and OSX cover large areas of functionality not really covered by the linux kernel (e.g. windowing systems) and the Linux kernel covers a wider range of devices than Windows or OSX so will have more a larger driver base.
Various closed source vendors discourage that even to the point of suing people for reporting vulns while keeping known ones secret.
In 2013 they paid out $100k to a single researcher for a set of bug reports.
So I don't think in a comparison of OS-->OS bugs that factor would really apply
I know this is probably meant to be read by people who know more about the subject than me, but adding some axis labels wouldn't hurt.
http://kernsec.org/wiki/index.php/Kernel_Self_Protection_Pro...