Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This isn’t a guessing game. Zero day has a very specific meaning. Just because something isn’t patched doesn’t mean it can’t be mitigated (i.e. disable the service) so no, patching is not the most important. Disclosure is.


By defense I meant patch or mitigation. When using the sysadmin hat, I don't care when the bug was discovered or disclosed, I only care about when was it fixed, or how can it be mitigated.

Sorry my reply came so late.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: