Re: The Register: OpenVMS among most-secure of operating systems

From: Andrew Harrison SUNUK Consultancy (Andrew_No.Harrison_No_at_nospamn.sun.com)
Date: 01/08/04


Date: Thu, 08 Jan 2004 17:00:42 +0000

Keith Parris wrote:
> Software vulnerabilities still dog operating systems
> http://www.theinquirer.net/?article=13420
>
> "Proprietary systems are the least vulnerable
>
> The operating systems with fewest vulnerabilities in 2003 are HP's
> OpenVMS, IBM's OS/400 and IBM's zOS.
>
> These three are all proprietary and they all have security that is
> fully integrated, not applied as some kind of after-thought. Certainly
> they come with a decent price-tag but they can be well worth the money
> when the result is fewer security problems, less unscheduled downtime
> and less downtime for patching."
> ...
> "the most secure operating systems continue to be certain proprietary
> systems from HP and IBM. Some may refer to these more secure systems
> as legacy systems but if legacy means secure and reliable it seems
> that legacy should be the preferred option."

Unfortunately its a pointless piece of research because OpenVMS
security advisories do not get reliably reported to CERT, Bugtraq
etc so counting the ones that do only catches the excpetions to
the rule.

You know this, I know this, its well documented so why did you
bother posting a reference to the The Registers article its
not very responsible behaviour on your part is it.

Regards
Andrew Harrison



Relevant Pages

  • Re: PSA: Windows PCs face huge virus threat: 1990 - Present
    ... >Why do these vulnerabilities continue to exist and be exploited in Windoze? ... and the result is that all modern operating systems are ... But very secure isn't the same as completely secure. ... If you were Bill Gates, you would be better off investing in new ...
    (sci.astro.amateur)
  • The Register: OpenVMS among most-secure of operating systems
    ... The operating systems with fewest vulnerabilities in 2003 are HP's ... Some may refer to these more secure systems ... as legacy systems but if legacy means secure and reliable it seems ...
    (comp.os.vms)
  • Re: Pentesting tool - Commercial
    ... I common approach is to do a full test using a lot of tools that address known vulnerabilities, common design flaws and such - in combination with penetration testing tools to sort of false positives and confirm what sort of consequences a breach would have. ... In combination with firewall policy analyzes, looking at the routines surrounding security all the way from development to maintenance you'll have some sort of baseline to work out from when it comes to the level of security. ... I want them to acquire secure software and use it ...
    (Pen-Test)
  • RE: Fwd: Terminal services and remote programs.
    ... "help/about vulnerabilities" that were mentioned here a few days ago. ... TerminalServices and RemoteApp deployments, including ... Need to secure your web apps NOW? ...
    (Pen-Test)
  • RE: Fwd: Terminal services and remote programs.
    ... Our team regularly breaks into Terminal Servers ... Need to secure your web apps NOW? ... Cenzic finds more, "real" vulnerabilities ...
    (Pen-Test)