Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What does "zero-day" even meant?

> ... decade-old ...

> ... was exploited in the wild ...

> ... may have been part of an exploit chain....



The vulnerability has been present for more than a decade.

There is evidence that some people were aware and exploiting it.

Apple was unaware until right now that it existed, thus is a 'zero day' meaning an exploit that the outside world knows about but they don't.


I don’t see any evidence it was there for a decade


Meaning unknown to the public/vendor



Well whatever the zero means, it can't be the number of days that the bug has been present, generally. It should be expected that most zero-days concern a bug with a non-zero previous lifespan.


“Zero day” has meant different things over the years, but for the last couple-ish decades it’s meant “the number of days that the vendor has had to fix them” AKA “newly-known”.


It still weirds me out that a term w@r3z d00dz from the 90s coined is now a part of the mainstream IT security lexicon.


Consider that there's probably a large overlap between those groups


Old-timers, at this point, but I take your point. I guess, for that matter, the terms "social engineering" (as it relates to manipulating people into divulging secrets, etc) and "doxxing" both came from the same community, too. How bizarre. Terms that were bandied about by kids in text files became actual industry jargon (and, in the case of "doxxing", arguably mainstream).


Right, I think the use of "0-day" as "stolen, unreleased software by software pirates" predates the current use.

The other commenter is right, there's a lot of overlap in the communities. It's strange to me that I was in the "field" a good 20 years before I ever thought it would be a career opportunity. This is not a complaint by any means. :-)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: