5 ms·
The version that includes the fix was released a few days ago... how is this a 0-day at this point?
by ktjfi 8y ago
The version that includes the fix was released a few days ago... how is this a 0-day at this point?
- smsm42 8y agoI think people who don't know what 0-day actually used to mean use it in a sense of "new security bug". Classically, no 0-day can by definition have a CVE, for example. But right now any new bug which is widely exploitable in the wild can be called in the press "0-day", despite the fix being released.
- arcticfox 8y agoIt was exploited before the vendor was aware; IMO that earns it a permanent "Zero-day" title. Obviously it's not currently a zero-day, given that we're hearing about it from the vendor. The moniker is pretty paradoxical otherwise, the discoverer writing a post about a zero-day would make it no longer a zero-day.
- kbenson 8y agoI always thought it was from the patch date. As I understand it there are 1-days, and 2-days, where people rush to make exploits for released patches to capitalize on the lag time between patch availability and wide deployment (and also zero-days which were recently patched), which is why zero-day denotes that there has been no time since a patch is available (since there isn't one). So, I would say this was a zero-day up until the point Chrome released a patch, and as of now it's some low X-day.
- busterarm 8y agoYou're both wrong for different reasons. 0day refers to vulnerabilities. t0 is when a vulnerability is discovered. t1 is either when the vendor issues a patch OR it is exploited and t2 is when >50% of vulnerable systems have applied the patch. tl;dr: something is 0day once it's discovered. It is no longer 0day once an action is taken with the vulnerability.
- feanaro 8y agoSo it's possible that t1 < t0? Because something might had been exploited before whatever time is taken as the official "discovery date".
- short_sells_poo 8y agoI assume it is 0day irrespective of who discovered it. It remains 0day until an action is taken to mitigate it. So you have 0day exploits being traded on various markets - those are exploits which are known to certain groups, but the affected party hasn't yet taken action to mitigate them (most likely because they don't know).
- deleted 8y ago[deleted]
- tills13 8y agoThe post reads more like an anti-Chrome post than about the exploit.
- kerng 8y agoCurious to learn how long its was exploited before Google noticed.. days, months, years?