# \[POLL\] What type of OS Exploit is Worse?

**URL:** https://www.twit.community/t/poll-what-type-of-os-exploit-is-worse/3002
**Category:** Security Now
**Created:** [October 24, 2019, 1:07am UTC](https://www.twit.community/t/poll-what-type-of-os-exploit-is-worse/3002 "2019-10-24T01:07:01Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![CREASE](https://sea2.discourse-cdn.com/flex020/user_avatar/www.twit.community/crease/32/1953_2.png) [@CREASE](https://www.twit.community/u/CREASE)
#### Post date: [October 24, 2019, 1:07am UTC](https://www.twit.community/t/poll-what-type-of-os-exploit-is-worse/3002/1 "2019-10-24T01:07:01Z")

</div>

More and more exploits roam the black market or are used by state actors for years and years before finally entering the public realm as 0-days. Others are revealed by security researchers or plain hackers as 0-days; new to everyone. Which is worse? They are both critical exploits… Leave your thoughts in the comments.

_Poll ([view on site](https://www.twit.community/t/poll-what-type-of-os-exploit-is-worse/3002/1))_

---

<div class="post-metadata">

### Author: ![PHolder](https://sea2.discourse-cdn.com/flex020/user_avatar/www.twit.community/pholder/32/2439_2.png) [@PHolder](https://www.twit.community/u/PHolder)
#### Post date: [October 24, 2019, 1:27am UTC](https://www.twit.community/t/poll-what-type-of-os-exploit-is-worse/3002/2 "2019-10-24T01:27:19Z")

</div>

Any exploit is bad, but being subject to one which you had no possibility to avoid (because there was no patch available) seems much worse than being hit by one you could have patched for.

---

<div class="post-metadata">

### Author: ![CREASE](https://sea2.discourse-cdn.com/flex020/user_avatar/www.twit.community/crease/32/1953_2.png) [@CREASE](https://www.twit.community/u/CREASE)
#### Post date: [October 24, 2019, 1:35am UTC](https://www.twit.community/t/poll-what-type-of-os-exploit-is-worse/3002/3 "2019-10-24T01:35:25Z")

</div>

> [@PHolder](#):
>
> one you could have patched for

or changed your habits to avoid or mitigate for. Agreed @PHolder

---

<div class="post-metadata">

### Author: ![big\_D](https://sea2.discourse-cdn.com/flex020/user_avatar/www.twit.community/big_d/32/1023_2.png) [@big\_D](https://www.twit.community/u/big_D)
#### Post date: [October 24, 2019, 6:08am UTC](https://www.twit.community/t/poll-what-type-of-os-exploit-is-worse/3002/4 "2019-10-24T06:08:23Z")

</div>

At least the publicly released ones, even if there is no patch, are known and you can take actions to avoid them, even if it means taking the affected devices offline until a patch has been released.

If it is only known to the bad guys, you are wide open to being exploited.

---

<div class="post-metadata">

### Author: ![sadpanduar](https://sea2.discourse-cdn.com/flex020/user_avatar/www.twit.community/sadpanduar/32/1982_2.png) [@sadpanduar](https://www.twit.community/u/sadpanduar)
#### Post date: [October 24, 2019, 2:54pm UTC](https://www.twit.community/t/poll-what-type-of-os-exploit-is-worse/3002/5 "2019-10-24T14:54:07Z")

</div>

[James Stavridis: How NATO’s Supreme Commander thinks about global security](https://www.youtube.com/watch?v=QPiaadMporw) Back in 2012 this military commander knew that secrets cut both ways and that openess has power.

---

<div class="post-metadata">

### Author: ![knewman](https://sea2.discourse-cdn.com/flex020/user_avatar/www.twit.community/knewman/32/1153_2.png) [@knewman](https://www.twit.community/u/knewman)
#### Post date: [October 24, 2019, 3:07pm UTC](https://www.twit.community/t/poll-what-type-of-os-exploit-is-worse/3002/6 "2019-10-24T15:07:57Z")

</div>

Depends who you and your adversaries are. The majority of people are more susceptible to passive attacks lingering in the internet background radiation which are typically publicly known exploits. If you’re being actively targeted then it’s more likely that your adversary is using a zero day.

So publicly known exploits probably have a much broader scope with minimal impact (i.e your CC number is now part of a dump for sale on a hacker forum), but black market exploits will have a much finer scope with a potentially serious impact (i.e. your enrichment centrifuges are being torn to shreds).

---

<div class="post-metadata">

### Author: ![dking](https://sea2.discourse-cdn.com/flex020/user_avatar/www.twit.community/dking/32/1130_2.png) [@dking](https://www.twit.community/u/dking)
#### Post date: [October 24, 2019, 3:22pm UTC](https://www.twit.community/t/poll-what-type-of-os-exploit-is-worse/3002/7 "2019-10-24T15:22:24Z")

</div>

No question. Black market / state actors are worse. Once a 0 day hits and is known, most vendors issues patches pretty quickly, impossible to do when the threat is not disclosed.
