Live data from Hacker News

Where the term "Zero Day" comes from

markmaunder.com

21–30 of 45 posts

Re: Where the term "Zero Day" comes from

#21

today drug dealers use leet speak over SMS to communicate about transactions without triggering local LE detection

I didn't know that. Do you have a source for this information?

I just know my my children rebel by buying Apple products and have no technology skills. (Their rebellion choices could be way worse) They use "leet" speak on sms. I always hated it and didn't use it in my OLD warez days on the C64 NASA (North Atlantic Software Alliance) cool name huh? :)

Re: Where the term "Zero Day" comes from

#22
post #18

Earlier quoted context omitted.

I didn't know that. Do you have a source for this information?

I wonder if this is just a retelling of the myth(?) that leet speak originated in the practice of renaming files to avoid detection by sysadmins.

I seriously think it was all the crazy warez custom title screen that could be larger then the actual game. Back then you had to be "known" and go through the initiation of making sure you weren't someone that could harm them through intent or stupidity.

Re: Where the term "Zero Day" comes from

#23
post #4

Yeah, I've been curious for a while as to how "zero day" morphed into its current, completely unrelated non-sequitur meaning. I'm guessing it's more or less the same way "hacker" came to mean "computer criminal"--buncha noobs parroting actual hackers' lingo without understanding, in hopes of seeming cool.

I wouldn't call the current usage a non-sequitur. Zero-day exploits being those in use before the vendor and general public have been made aware of them. Presumably, a 1 day exploit would be one published on the day the vulnerability was announced. It seems like a fairly natural application of what was, at the time, a pretty well understood terminology.

The problem is, current usage seems to be to use 'zero day' as a synonym for 'just released' when speaking about vulnerabilities, which I agree is wrong. A '0day' by definition will not be known about by the public, so cannot feature in a public announcement.

Re: Where the term "Zero Day" comes from

#24
oh memories... Some were a bit more lazy and used "trashed" credit card numbers to get free phone calls... They were looking in some restaurant's trash can to get them... Not exactly hi-tech but working nonetheless :-)

Re: Where the term "Zero Day" comes from

#25

Earlier quoted context omitted.

I remember using Toneloc during that time to wardial entire exchanges looking for dialup modems into servers. I wonder how many people I annoyed with getting phone calls in the middle of the night with my 14.4 modem screeching in their ear.

ToneLoc author here (mthreat), checking in, 20 years after the release of the last version. I didn't manage to avoid the federal prison part, but somehow ended up fine in the end. My path, roughly: BBSes -> saw WarGames -> wannabe hacker -> warez boards (Public Enemy) -> cracking games (learned x86 asm) -> hacking voicemail boxes -> wrote ToneLoc (learned C) -> real hacking -> COSMOS access -> physical hacking (burgl…

I can't believe the author of ToneLoc posts here. This blows my mind! Brings up a lot of memories of great times, hanging out at the st. louis galleria food court for 2600 meetings.

Re: Where the term "Zero Day" comes from

#26

And if you didn't have 16550AFN serial and a USR Courier HST your 0-day was likely to turn into a 3-day... I remember taking advantage of call waiting tones to dump friends offline and steal their places on local multi-user BBS. Good days!

Oh man I've just remembered my big old mean USRobotics Courier. When I got that, I thought I'd hit the big time.

Re: Where the term "Zero Day" comes from

#28

Earlier quoted context omitted.

I remember using Toneloc during that time to wardial entire exchanges looking for dialup modems into servers. I wonder how many people I annoyed with getting phone calls in the middle of the night with my 14.4 modem screeching in their ear.

ToneLoc author here (mthreat), checking in, 20 years after the release of the last version. I didn't manage to avoid the federal prison part, but somehow ended up fine in the end. My path, roughly: BBSes -> saw WarGames -> wannabe hacker -> warez boards (Public Enemy) -> cracking games (learned x86 asm) -> hacking voicemail boxes -> wrote ToneLoc (learned C) -> real hacking -> COSMOS access -> physical hacking (burgl…

Heavy. Now that's a journey. I remember ToneLoc and I may have used it - although we envied you Americans at the time because local calls were not free for us.

Re: Where the term "Zero Day" comes from

#29
post #23
post #4

Earlier quoted context omitted.

I wouldn't call the current usage a non-sequitur. Zero-day exploits being those in use before the vendor and general public have been made aware of them. Presumably, a 1 day exploit would be one published on the day the vulnerability was announced. It seems like a fairly natural application of what was, at the time, a pretty well understood terminology.

The problem is, current usage seems to be to use 'zero day' as a synonym for 'just released' when speaking about vulnerabilities, which I agree is wrong. A '0day' by definition will not be known about by the public, so cannot feature in a public announcement.

Zero day, today, means unpatched in latest version, at least when applied to vulnerabilities.
Post reply on HN