Vulnerability Numerology – Defective by Design?

On Slashdot, rdmreader : writes:

“RDM has a point by point disassembly of the security vulnerability story phenomenon. We regularly see these, comparing various vulnerability lists for different operating systems. ZDNet’s George Ou, for example, condemns linux and mac os X by tallying up reported flaws and comparing them against Microsoft’s. What he doesn’t note is that his source, Secunia, only lists what vendors and researchers report. Results selectively include or exclude component software seemingly at random, and backhandedly claims its data is evidence of what it now tells journalists they shouldn’t report. Is Secunia presenting slanted information with the expectation it will be misused?”

I’ve made that point multiple times in the past: Always look at what’s behind statistics. Look at sample size, look at methodology. It looks as if 64.83% of all statistics are invented on the spot; as for the rest, a surprising number of so-called “results” are in fact barely disguised PR efforts made out of half- and full – lies.

I am truly getting sick and tired of folks lying to me ” for my own good.”

Comments are closed.


Bad Behavior has blocked 26 access attempts in the last 7 days.