I think you misunderstand. "Better documented" means there are more people out there poking and proding looking for weaknesses so we have a better idea of what the weaknesses are. That's a fact.
No, that is really not a fact.
Are you saying the general "hacker" knows more about IIS than Apache?
No windows service can be better documented to the public than a "OS X" service, simply because the OS X part will be open-sourced. It will also run on a lot of different operating systems(BSD, GNU/Linux etc.).
For IIS you need to poke and prodd, you are fumbling in darkness due to the lack of any source-code. The Apache source-code is openly available. So is the rest of Darwin. How does this make Apache "secure trough obscurity" and IIS not?
its just simple probability that if 90% of the people who write viruses are PC users, 90% of the viruses out there will be PC viruses.
Yes, this I can relate to.
But, this is also true for Linux. Who makes email-viruses for Linux?
I can appreciate the fact that 90% of the world uses Windows, thus anything not Windows has security trough obscurity. I think it's a pretty strange statement, but I can see how someone might assert this.
BUT, when you try to put Linux in the same group as Windows, leaving out the BSD's and OS X, you would be way of base IMO.
From where I stand, the joint efforts of Apple's Darwin Core Team, FreeBSD, NetBSD and OpenBSD and the usage of theese opearting systems will exceed the same efforts for Linux. Especially since the only thing Linux has going is the Kernel. The "Linux userland"(which doesn't even exist) is a chaotic jungle where very little joint effort is happening. This is also considered to be a somewhat weakness of the Linux plattform. I believe there is a chapter of POSIX that was supposed to handle some of this:
http://standards.ieee.org/reading/ieee/std_public/description/posix/1387.2-1995_desc.html
Thus, if OS X has security trough obscurity, so does the Linux distroes, the BSD's and especially the pure UNIX'es(Solaris, HP/UX, Irix. Not even sure if they still have the Unix trademark). The Unix specification seems to mostly be a thing of the past, and I don't really see any value to following it.
And, yet,
I would still not say that OS X has security trough obscurity simply because 90% of the world uses Windows.