Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Can confirm. "Zero day" means you've had zero days to patch. The term has been used this way since, IIRC, the late 1990s. See Phrack 53 for an example:

http://www.textfiles.com/magazines/PHRACK/PHRACK53



If the bug was found 91 days before the fix and was released one day before the fix. Others might argue that it is a 91-days or a 1-day :))

Tl;dr: it doesn't matter. A low-severity bug was found, and then was fixed.


Wrong. "zero day" means the _vendor_ has had zero days notice. Few companies and even users patch the same day a fix comes out.


Words are used to communicate, and language is fluid and changes over time. Clearly, zero-day is being used and understood by many to mean simply "unpatched", and so that is a reasonable definition. If ever you're arguing that a significant proportion of people are using language incorrectly, you're probably on the wrong side of history.


Don’t you just love it when people pull out their dusty tomes to prove to you that you’re wrong? It’s so pedantic yet also incredibly ignorant of how dynamic languages are.

I got yelled at once for using the word “cheap” to mean “inexpensive” once and wish you had been there with me.


I think a "zero day" threat model and terminology is from the point of view of the blue team type of people running the system, not the vendor.

From someone running a system, it doesn't matter if the vendor had 0 prior knowledge of the vuln or if they had made 25%, 50% or even 99% progress towards a patch. The point is there is still no patch available for the vulnerability and your only defense strategies are the same as if the vendor hadn't known at all, so it's still a 0day.


If the vendor has had zero days notice then nobody has had any time to patch, so my statement stands.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: