Tech●●●●●Difficulty 4 of 5

What is a zero-day, and why do companies pay hackers to find bugs?

A flaw that its maker does not know about can sell for millions, and the vendor itself may offer only a bounty.

▶ Start the story

A zero-day is a security hole in software that nobody who could fix it knows about. The name comes from the old counting of days since release: "zero-day software" was obtained by hacking a developer's computer before the public could get it, and the term moved on to the flaws behind that hacking and to the number of days a vendor has had to fix them. Virtually all products contain bugs. A bug that creates a security risk is a vulnerability, and the most dangerous let an attacker run their own code without the user being aware.

Zero-days are dangerous because there is no patch: all systems with the flaw are at risk, even banks and governments with every patch up to date. Yet they are not the usual way in. It is likely that most cyberattacks use known vulnerabilities, not zero-days. They are mainly used by governments, because finding or buying one, and writing the attack software, is costly.

That cost makes a market. Zero-day exploits can fetch millions of dollars, and there are three main kinds of buyers: "white" ones like the vendor, "gray" ones like government and intelligence agencies, and "black" ones in organized crime. The trade tends to be secretive: if the vulnerability becomes known, it can be patched and its value crashes.

Who buys a zero-day?

Vendor bounty (white market)

  • Fix the flaw
  • Recognition and money
  • Estimated at least ten times smaller than the other two

Governments and criminals

  • Use or stockpile it
  • Can fetch millions
  • Secret: public means patched

The vendor's alternative is the bug bounty: a deal offering recognition and money to people who report security bugs. In 1983 a company offered a Volkswagen Beetle for bugs in its operating system, and Netscape ran a bounty in 1995. The catch is that hackers could earn much more selling a bug to brokers, spyware firms or governments, so a bounty often competes with a far richer market.

Quiz me

0/3

  1. 1.Why is a zero-day particularly dangerous?
  2. 2.Why can a bug bounty be hard to compete with?
  3. 3.What happens to a zero-day's value if it becomes public?

Recap

A zero-day is worth money only while it stays secret: once known, it can be patched and its value crashes.

💡 A trick to remember it · Zero days to fix means zero patch; a bounty is a price tag set against the secret market.

Surprising fact · Zero-day exploits can sell for millions of dollars.

Sources (2)

No source, no claim. Every fact in this lesson (16 claims) cites at least one of these.

  1. [1]Zero-day vulnerability · Wikipedia
  2. [2]Bug bounty program · Wikipedia
More lessons in 💻 Tech (3) See all tech lessons →

One more light on your map.

Get one lesson like this every day, about the things you love. Free, in two or five minutes.

Get the share card for this lesson ↗