Why Windows is less secure than Linux | Threat Chaos | ZDNet.com

Why Windows is less secure than Linux | Threat Chaos | ZDNet.com

Ever wondered why impartial experts claim Windows is more difficult to secure? (Not less secure, more difficult to secure. Don’t flame me.) This article uses diagrams to graphically illustrate the answer. In short, a Windows+IIS combination is more internally complex and therefore, offers more potential points of failure.

CC BY-SA 4.0 Why Windows is less secure than Linux | Threat Chaos | ZDNet.com by Stephan Sokolow is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.

This entry was posted in Geek Stuff. Bookmark the permalink.

3 Responses to Why Windows is less secure than Linux | Threat Chaos | ZDNet.com

  1. MikeT says:

    As I pointed out, this seems to be more of an indictment of IIS than Windows. IIS is known for being a really, really bad web server. Microsoft had to rewrite it from scratch in their last iteration, IIRC, because it was so bad in previous iterations. The fundamental point still stands that Windows is more complicated, but I don’t think this blog post makes that case.

  2. An interesting contrast would be to see a third diagram, namely one that shows the system call behaviour when one serves up the very same web pages on an instance of Apache running on Windows.

    That would drop out differences having to do with IIS, and show what Windows does when presented with what *ought* to be a similar set of OS requests.

    In principle, that might be more of a direct “OS versus OS” comparison.

    Although the Byzantine linkages between IIS and Win32 is very interesting to observe…

  3. ssokolow says:

    Both good points. As your comments make good counterpoints, I’ll leave this post as it is.

    Besides, it’s unnecessary hassle to both correct the post and keep an unaltered copy in accordance with my personal policies regarding information. (It’s no accident that my main website uses a permissions-restricted wiki as a content management system)

Leave a Reply

Your email address will not be published. Required fields are marked *

By submitting a comment here you grant this site a perpetual license to reproduce your words and name/web site in attribution under the same terms as the associated post.

All comments are moderated. If your comment is generic enough to apply to any post, it will be assumed to be spam. Borderline comments will have their URL field erased before being approved.