You are viewing a single comment's thread from:

RE: My 2024 goal - Wishing for No Zero days in 2024

in LeoFinancelast year (edited)

Zero day is the day when we don't feel like doing anything and we don't do anything related to our goals or dreams.

Well, actually "zero days" have another meaning to me. When a software project maintainer finds out about an vulnerability in software and there are zero days to fix it because after zero days it will be known by malicious people. In other words, its already being used against people.

In the best cases a white hat hacker finds a problem and reports it privately so it can quietly be fixed and then once everyone has updated copies credit can be given.

Earlier this month, I got a security update for GNU-TAR. GNU TAR! Tar is the archiving program (for Linux, Unix) that is so old it was originally designed to pull files off of digital tapes. When such an important and commonly used program in Linux still had a security hole a month ago, we should set our expectations that there are holes in a lot of things which are newer. And when I say newer than TAR, that is pretty much every software out there these days!

Sort:  

Well said. I recently had a similar issue in my day job where there was a vulnerability and I had nearly a week before it became a security issue. Had to work my ass off to fix it before it becomes critical. Literally Zero days and I had to send the fix live.