That is not actually the origin of the term "zero day"; "zero day" is a tongue-in-cheek #hack expropriation of #warez jargon, where "zero days" refers to the number of days from the official release date of a piece of pirated software.
The article isn't trying to explain the origin of "zero day". The article is defining it in the context that it's used for the benefit of their readers.
> That vulnerability in Internet Explorer was known as a “zero-day” because Microsoft, the targeted software maker, had zero days notice to fix the hole when the initial attacks exploiting the bug were discovered.
So is that the point you were originally trying to make instead of discussing etymology? While we're quibbling prescriptively about terminology, I'd argue that the IE exploit patched earlier this week was in fact a zero day since it was not public knowledge.
> The vulnerability underlying CVE-2013-3897 was found internally at Microsoft and would have been fixed in MS13-080. However, in the last two weeks, attacks against the same vulnerability became public, but since the fix was in the code already, it enabled Microsoft to address the vulnerability, CVE-2013-3897, in record time.
how I remember it, crackers used the term before the warez groups did. it meant having a crack for software on the same day it was released.
in warez it was a folder on the ftp server that would list all the latest releases from that day, to save you from navigating all the /pub/whatever folders over your slow 14.4k connection and so that the distributors would only have to grab from one place.
and somehow in this history the pronunciation changed from "oh day" to "zero day" and was re-appropriated as an infosec term.
edit: just read the definition in OP, it is hilarious.
I mean, it carries the implication of not giving vendors time to fix, in a way, but that's not at all what it means. There are plenty of zero days vendors know about but haven't patched yet.
I thought it referred to the time elapsed between the pirated release being made, and your having access to it. How high up the chain you are. Hence the inevitable escalation to 0hour, 0sec as bandwidth increased over the years.
I always thought it was like "patient 0". The day-counting started once the exploit was first exploited, meaning the first to exploit it was doing so on the 0th day.