The fact is that most hacks are from vulnerable services running and social engineering, the latter is totally excluded by this methodology and were the services realistic? , web with cgi , database , dns ,smtp ,ssh.... Targetting many times occurs due to what services you are runing already which was also excluded in this test. Anyone can put any updated firewalled box with no vulnerable services running up and no one will hack it unless they are very leet or have friends who are. From a purely scientific pov All this proves is that pooh can run windows update and configure a firewall properly, probably as far as i can see so.
