What’s up with the jargon “zero day”?
Why not just say “previously unknown”?
I’m often pro-jargon. I.e. I think a lot of jargon exist for good reasons, so I’m open to this one also being good in some way. E.g jargon can be useful for naming precise technical concepts.
Anyone want to defend “zero day” jargon?
No steel-maning please!
I.e. only want answers from people who genuinely think that this is a good jargon.
Update:My question has been answered in the comments.
0-day means something distinct from “previously unknown:” no patch available. N-day means the number of days a patch has been available. A vulnerability in an old version that was previously unknown yet coincidentally is already fixed by an extant patch is previously unknown, but not a zero-day.
More people seem to use it to mean that the software maintainer has had no time to react to the vulnerability. It’s a zero-day when I find it, a one-day when I report it, and very possibly a 180-day when you release your actual patch for it. But quite a few people also seem to use it the way you suggest. It’s always about how long some “reference defender” has known about it, but people’s idea of who the “reference defender” is seems to vary.
What’s up with it: fits the hacker aesthetic. Why it’s good: succinct and cool. Where it’s from: originally referred to software pirated before its public release, as opposed to x days after release.
It was a precise technical concept for a mostly niche industry, specifically information security workers. An incredibly important industry, to be clear, but the total number of people in it is a fraction of a fraction. There’s been a lot of talk about zero days lately with LLMs getting good at creating them, but ten years ago I’d have expected more people to need to know “hypotension” (medical jargon) or “Roth IRA” (finance jargon) than needed “zero day.”
“Zero day” is a bit different from “we didn’t know about it.” As other commenters have mentioned, the zero in zero day is about how long a patch for the exploit is out. Put it another way; if tonight the New York Times wrote about a new exploit, and for some reason the entire security world collectively decided ‘nah, someone else will handle that, I’ve got other stuff to do than fix that one’ for a week, the exploit would still be called a zero day a week later. It’s known, but there’s no patch. Why is that important? Because the legion of competent information technology workers working at most companies are usually on top of things enough to apply updates and patches, but not capable of writing their own countermeasures.
Citation: Professional experience. I used to work I.T. for a university, and I knew to update computers I found that didn’t have their patches, and knew how to set things up so the network would prompt all the computers to update or at least tell me what computers I hadn’t gotten to yet. An exploit with a seven day old fix wouldn’t (in theory!) work on us. But that approach doesn’t work for exploits with no patch, and I couldn’t write the patch. (I usually didn’t have access to the source code for our software- like, imagine there’s an outright bug in the Windows login code, and Microsoft isn’t fixing it. Decompiling the source and fixing that is way above the pay grade for a random I.T. worker, and would have violated terms of service!) In practice, that’s fine. Microsoft had a lot of smart people working hard to fix any exploits they saw, and since exploits Microsoft hadn’t fixed yet were rare, nobody was going to use one to go after my employer.
TLDR: Zero day doesn’t mean ‘we don’t know about the exploit’ it means ‘nobody has published a fix for the exploit.’ That matters because most tech workers can counter exploits where there’s a published fix (they hit the “Apply Windows Update” button) but most can’t stop exploits where there’s no published fix.
Suppose there is a set of components connected by a communication network. Each of the components has a configuration, for example, an operating system configuration. Suppose a vulnerability is discovered on a certain date, DD the discovery date. It takes P days to develop a patch. So the patch is available at DD plus P. If the set of components is large, it can take a number of days between when the patch is available and when the patch is installed, mitigating the vulnerability. So each component C_i is “repaired” at DD plus P plus C_i.
For example, a self propagating “worm” is effectively unmitigated for P days after DD. How fast it can replicate during those P days is an important question. For fast replicating worms, it may be that P has to be low, even zero, to kill the worm. But the important point is that on day zero after discovery no one is protected against the worm. If you seek to have a sense of confidence about the security of your subnetwork, a “zero day“ vulnerability is the sum of all fears. To rebuild your confidence, you must rebuild your subnetwork, which is expensive.
An attacker then seeks out zero day vulnerabilities, exactly because no one can be certain that they are protected against it—even the most well funded adversaries. Additional resources can bring P arbitrarily close to zero, and in the common era AI security defenders can make that cost many orders of magnitude below what it once was. Nevertheless, the zero day vulnerability keeps some of its power when an attacker can discover multiple of them on the same day. Again, in particular, the treasured sense of security is lost.
This is mostly how language works? Language is semi-arbitrary phonemes that are assigned meanings based on historical usage and mutual understanding. This jargon is long standing and widely understood by practitioners.
“Zero day” actually means something different from “previously unknown”. Many “zero day” vulnerabilities are actually previously known to someone. For example, the NSA is presumably sitting on a pile of “zero day” vulnerabilities, judging from what was revealed about their Tailored Access Operation programs in the past. Similarly, I have heard from pentesting people claim that some pentesting companies supposedly keep a “zero day” or two in their back pocket to ensure that their important pentests produce some results. In general, attackers have a strong incentive to stockpile “zero days,” and to selectively deploy them against high value targets when needed.
So “zero day” is actually a shorthand for something like “vulnerability previously entirely unknown to vendors/maintainers and defenders at large, but potentially privately known to one or more attackers.” It might, in limited circumstances, even include vulnerabilities that have been previously used against low-awareness defenders, if the attacker successfully evaded any recording mechanisms or post-motem detection.
Better, but it’s still glossing over the critical bit, which is “previously unrevealed to who?” Specifically, “zero day” implies both that:
The vendor or maintainers had no idea of the vulnerability’s existence.
A diligent defender would have zero days to prepare, hence the name.
Meanwhile, it’s entirely possible that the attacker has known for months or years.
Words like “unknown”, “unreleased”, etc., are all imprecise about this asymmetry. For example, if Microsoft knows about a vulnerability in Windows but hasn’t shared that information with the public, that’s “unrevealed” to the public. But most people would not consider it a zero day.
“Zero day” is an established term that is widely understood by practitioners and the relevant professionals. It might not be an ideal choice of terminology when writing a newspaper article for a non-technical audience.
situating the vulnerability in the context of the mathematical model of network connected components, reminding you that you are (inevitably) part of a security community (weakest in the whole due to it’s weakest links, etc); and
a nostalgic recall to the youth of the industry where a “zero day” was rare and valuable rather than manufactured multiple times per day on demand.
Given that it is the computer security community that will determine whether we recover from the first AI worm within days (annoying), weeks or else months (cross-industry phase change event), it likely behooves us to use their language. for example, this impossible situation immediately demands a security office at Anthropic and OpenAI that can help respond to AI worm emergencies. Do the facilities exist? if not, they have a higher chance of being established and effective if the frontier labs engage now with the security community and their language. the idea of multiple zero day vulnerabilities per day should make any security professional nauseous.
“Zero day” sounds much cooler than “previously unknown” which is consistent with the great prestige of finding one (well, it was before Mythos). Don’t forget that academics only find a small share of all zero days, so I don’t believe they have or should have the ability to prescribe that others use sterile terms.
It was previously called a “zero-day exploit”. It referred to the time after a vulnerability was published for a corresponding exploit to appear. A zero-day exploit is one that appears together with the security vulnerability, leaving the software maintainer zero days to fix the vulnerability before anyone can exploit it.
Later people started to call security vulnerabilities for which a zero-day exploit exists “zero-day vulnerability” or just “zero day”.
It’s a broadly adopted term of art that has more specific nuance than “previously unknown” and abbreviates nicely to “0-day”. What more do you want from jargon?
It’s fine to use longer or squishier descriptions if you need to write to the broad audiences, but it’s simply part of the language of the field, just like you used “jargon” instead of something more generic like “technical terminology”. Consider why you chose that word and see if the same arguments apply to “zero day”.
What I wanted was for someone to point-out/explain the more specific nuance that made this jargon worth it. This question has been answered in other responses.
TIL what a “zero day” is! Was always confused because of the Y2K problem—I thought zero days have something to do with calendars. (That didn’t make sense but I somehow didn’t consciously thought about the confusion.)
What’s up with the jargon “zero day”? Why not just say “previously unknown”?
I’m often pro-jargon. I.e. I think a lot of jargon exist for good reasons, so I’m open to this one also being good in some way. E.g jargon can be useful for naming precise technical concepts.
Anyone want to defend “zero day” jargon?
No steel-maning please! I.e. only want answers from people who genuinely think that this is a good jargon.
Update: My question has been answered in the comments.
0-day means something distinct from “previously unknown:” no patch available. N-day means the number of days a patch has been available. A vulnerability in an old version that was previously unknown yet coincidentally is already fixed by an extant patch is previously unknown, but not a zero-day.
More people seem to use it to mean that the software maintainer has had no time to react to the vulnerability. It’s a zero-day when I find it, a one-day when I report it, and very possibly a 180-day when you release your actual patch for it. But quite a few people also seem to use it the way you suggest. It’s always about how long some “reference defender” has known about it, but people’s idea of who the “reference defender” is seems to vary.
What’s up with it: fits the hacker aesthetic.
Why it’s good: succinct and cool.
Where it’s from: originally referred to software pirated before its public release, as opposed to x days after release.
It was a precise technical concept for a mostly niche industry, specifically information security workers. An incredibly important industry, to be clear, but the total number of people in it is a fraction of a fraction. There’s been a lot of talk about zero days lately with LLMs getting good at creating them, but ten years ago I’d have expected more people to need to know “hypotension” (medical jargon) or “Roth IRA” (finance jargon) than needed “zero day.”
“Zero day” is a bit different from “we didn’t know about it.” As other commenters have mentioned, the zero in zero day is about how long a patch for the exploit is out. Put it another way; if tonight the New York Times wrote about a new exploit, and for some reason the entire security world collectively decided ‘nah, someone else will handle that, I’ve got other stuff to do than fix that one’ for a week, the exploit would still be called a zero day a week later. It’s known, but there’s no patch. Why is that important? Because the legion of competent information technology workers working at most companies are usually on top of things enough to apply updates and patches, but not capable of writing their own countermeasures.
Citation: Professional experience. I used to work I.T. for a university, and I knew to update computers I found that didn’t have their patches, and knew how to set things up so the network would prompt all the computers to update or at least tell me what computers I hadn’t gotten to yet. An exploit with a seven day old fix wouldn’t (in theory!) work on us. But that approach doesn’t work for exploits with no patch, and I couldn’t write the patch. (I usually didn’t have access to the source code for our software- like, imagine there’s an outright bug in the Windows login code, and Microsoft isn’t fixing it. Decompiling the source and fixing that is way above the pay grade for a random I.T. worker, and would have violated terms of service!) In practice, that’s fine. Microsoft had a lot of smart people working hard to fix any exploits they saw, and since exploits Microsoft hadn’t fixed yet were rare, nobody was going to use one to go after my employer.
TLDR: Zero day doesn’t mean ‘we don’t know about the exploit’ it means ‘nobody has published a fix for the exploit.’ That matters because most tech workers can counter exploits where there’s a published fix (they hit the “Apply Windows Update” button) but most can’t stop exploits where there’s no published fix.
Suppose there is a set of components connected by a communication network. Each of the components has a configuration, for example, an operating system configuration. Suppose a vulnerability is discovered on a certain date, DD the discovery date. It takes P days to develop a patch. So the patch is available at DD plus P. If the set of components is large, it can take a number of days between when the patch is available and when the patch is installed, mitigating the vulnerability. So each component C_i is “repaired” at DD plus P plus C_i.
For example, a self propagating “worm” is effectively unmitigated for P days after DD. How fast it can replicate during those P days is an important question. For fast replicating worms, it may be that P has to be low, even zero, to kill the worm. But the important point is that on day zero after discovery no one is protected against the worm. If you seek to have a sense of confidence about the security of your subnetwork, a “zero day“ vulnerability is the sum of all fears. To rebuild your confidence, you must rebuild your subnetwork, which is expensive.
An attacker then seeks out zero day vulnerabilities, exactly because no one can be certain that they are protected against it—even the most well funded adversaries. Additional resources can bring P arbitrarily close to zero, and in the common era AI security defenders can make that cost many orders of magnitude below what it once was. Nevertheless, the zero day vulnerability keeps some of its power when an attacker can discover multiple of them on the same day. Again, in particular, the treasured sense of security is lost.
This seems like an explanation of the history of the term, not a positive argument for its use.
This is mostly how language works? Language is semi-arbitrary phonemes that are assigned meanings based on historical usage and mutual understanding. This jargon is long standing and widely understood by practitioners.
“Zero day” actually means something different from “previously unknown”. Many “zero day” vulnerabilities are actually previously known to someone. For example, the NSA is presumably sitting on a pile of “zero day” vulnerabilities, judging from what was revealed about their Tailored Access Operation programs in the past. Similarly, I have heard from pentesting people claim that some pentesting companies supposedly keep a “zero day” or two in their back pocket to ensure that their important pentests produce some results. In general, attackers have a strong incentive to stockpile “zero days,” and to selectively deploy them against high value targets when needed.
So “zero day” is actually a shorthand for something like “vulnerability previously entirely unknown to vendors/maintainers and defenders at large, but potentially privately known to one or more attackers.” It might, in limited circumstances, even include vulnerabilities that have been previously used against low-awareness defenders, if the attacker successfully evaded any recording mechanisms or post-motem detection.
How about, “previously unrevealed”?
Better, but it’s still glossing over the critical bit, which is “previously unrevealed to who?” Specifically, “zero day” implies both that:
The vendor or maintainers had no idea of the vulnerability’s existence.
A diligent defender would have zero days to prepare, hence the name.
Meanwhile, it’s entirely possible that the attacker has known for months or years.
Words like “unknown”, “unreleased”, etc., are all imprecise about this asymmetry. For example, if Microsoft knows about a vulnerability in Windows but hasn’t shared that information with the public, that’s “unrevealed” to the public. But most people would not consider it a zero day.
“Zero day” is an established term that is widely understood by practitioners and the relevant professionals. It might not be an ideal choice of terminology when writing a newspaper article for a non-technical audience.
yes, the advocacy mainly comes from the term:
situating the vulnerability in the context of the mathematical model of network connected components, reminding you that you are (inevitably) part of a security community (weakest in the whole due to it’s weakest links, etc); and
a nostalgic recall to the youth of the industry where a “zero day” was rare and valuable rather than manufactured multiple times per day on demand.
Given that it is the computer security community that will determine whether we recover from the first AI worm within days (annoying), weeks or else months (cross-industry phase change event), it likely behooves us to use their language. for example, this impossible situation immediately demands a security office at Anthropic and OpenAI that can help respond to AI worm emergencies. Do the facilities exist? if not, they have a higher chance of being established and effective if the frontier labs engage now with the security community and their language. the idea of multiple zero day vulnerabilities per day should make any security professional nauseous.
“Zero day” sounds much cooler than “previously unknown” which is consistent with the great prestige of finding one (well, it was before Mythos). Don’t forget that academics only find a small share of all zero days, so I don’t believe they have or should have the ability to prescribe that others use sterile terms.
It generalizes nicely to how much time you have to patch the vulnerability before it is exploited.
It was previously called a “zero-day exploit”. It referred to the time after a vulnerability was published for a corresponding exploit to appear. A zero-day exploit is one that appears together with the security vulnerability, leaving the software maintainer zero days to fix the vulnerability before anyone can exploit it.
Later people started to call security vulnerabilities for which a zero-day exploit exists “zero-day vulnerability” or just “zero day”.
It’s a broadly adopted term of art that has more specific nuance than “previously unknown” and abbreviates nicely to “0-day”. What more do you want from jargon?
It’s fine to use longer or squishier descriptions if you need to write to the broad audiences, but it’s simply part of the language of the field, just like you used “jargon” instead of something more generic like “technical terminology”. Consider why you chose that word and see if the same arguments apply to “zero day”.
What I wanted was for someone to point-out/explain the more specific nuance that made this jargon worth it. This question has been answered in other responses.
Got it. You were after an explanation more than a defense and you got some good ones.
TIL what a “zero day” is! Was always confused because of the Y2K problem—I thought zero days have something to do with calendars. (That didn’t make sense but I somehow didn’t consciously thought about the confusion.)