3 ms·
The article isn't trying to explain the origin of "zero day". The article is defining it in the context that it's used for the benefit of their readers. > That
by jonchang 13y ago
The article isn't trying to explain the origin of "zero day". The article is defining it in the context that it's used for the benefit of their readers.
> That vulnerability in Internet Explorer was known as a “zero-day” because Microsoft, the targeted software maker, had zero days notice to fix the hole when the initial attacks exploiting the bug were discovered.
- tptacek 13y agoThat's not why the vulnerability was known as "zero-day".
- jonchang 13y agoSo is that the point you were originally trying to make instead of discussing etymology? While we're quibbling prescriptively about terminology, I'd argue that the IE exploit patched earlier this week was in fact a zero day since it was not public knowledge. > The vulnerability underlying CVE-2013-3897 was found internally at Microsoft and would have been fixed in MS13-080. However, in the last two weeks, attacks against the same vulnerability became public, but since the fix was in the code already, it enabled Microsoft to address the vulnerability, CVE-2013-3897, in record time. https://community.qualys.com/blogs/laws-of-vulnerabilities/2013/10/08/patch-tuesday-october-2013 https://community.qualys.com/blogs/laws-of-vulnerabilities/2... (unnecessary text omitted)