LWN.net Logo

Github compromised, or not?!

Github compromised, or not?!

Posted Mar 5, 2012 23:19 UTC (Mon) by PaXTeam (subscriber, #24616)
In reply to: Github compromised, or not?! by aliguori
Parent article: Github compromised

> An exploit was in the wild before the fix was available. That makes it a 0-day.

nope, it doesn't. and quoting wikipedia on it just shows how clueless both you and they are. first, the term '0-day' comes from the warez world where it had a different meaning ('fresh stuff', not released and traded anywhere else before that day, and the wiki is wrong on this meaning too, btw). since the late 90's it was then used for similar (initially) 'fresh stuff' traded among the hacker underground signifying the novelty of the exploit and the underlying security bug (read: unknown by anyone else). unlike a warez 0-day though which loses its 0-dayness after one day (there even used to be terms for 0-hour, etc), a 0-day exploit remains 0-day until either the exploit or the underlying bug becomes public. the Microsoft patch Tuesday has never had anything to do with the term, 0-day predates that event by a decade.

tl;dr: 0-day exploits are about bug/exploit secrecy, not fix availability.


(Log in to post comments)

Github compromised, or not?!

Posted Mar 6, 2012 8:24 UTC (Tue) by Los__D (guest, #15263) [Link]

I just love people who can't accept that an expression doesn't mean what it used to mean. They provide for hours of fun.

Github compromised, or not?!

Posted Mar 6, 2012 9:43 UTC (Tue) by epa (subscriber, #39769) [Link]

If you use bizarre and incomprehensible jargon like '0-day' instead of saying what you mean, then you deserve what you get.

Github compromised, or not?!

Posted Mar 7, 2012 14:11 UTC (Wed) by pboddie (subscriber, #50784) [Link]

Well, Wikipedia is a wiki, obviously, and you can always improve it by adding references to the proper definitions.

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds