3 ms·
Yes, it has essentially lost all meaning as most vulns are exploited before ever being reported. And even those who responsibly report them call them “0-days”,
by creeble 5y ago
Yes, it has essentially lost all meaning as most vulns are exploited before ever being reported. And even those who responsibly report them call them “0-days”, which is sort of true on the day they report them, but only if the company didn’t receive any other reports, and why would they divulge that information unless they had to, like to give someone else the bug bounty? “Sorry, it’s actually a 14-day, we’re working on the fix.” Right.
So again, it’s lost any useful meaning I think.
- jedberg 5y ago> as most vulns are exploited before ever being reported. I don't think that's even remotely true. And given that it's not true, it's still a useful distinction. 0-day means an exploit that is being exploited before it was reported to the vendor, which is different than most exploits, which are reported to the vendor first.
- creeble 5y agoI guess it's true that most vulns are either reported to (or originate from) a vendor, and that these dominate the CVE db. But naturally, unless you are the vendor, you will likely not have heard of these. Otherwise, by definition, they would be zero-day vulns.