I am sorry if you disagree, but with over 50,000 new samples of malware out daily I personally think that all of our time would be better spent on zero days that actually are hurting out users today.
Initial estimates are that more than half a million computers worldwide are infected with this Sony rootkit. Those are amazing infection numbers, making this one of the most serious internet epidemics of all time -- on a par with worms like Blaster, Slammer, Code Red and Nimda.
What do you think of your antivirus company, the one that didn't notice Sony's rootkit as it infected half a million computers? And this isn't one of those lightning-fast internet worms; this one has been spreading since mid-2004. Because it spread through infected CDs, not through internet connections, they didn't notice? This is exactly the kind of thing we're paying those companies to detect -- especially because the rootkit was phoning home.
But much worse than not detecting it before Russinovich's discovery was the deafening silence that followed. When a new piece of malware is found, security companies fall over themselves to clean our computers and inoculate our networks. Not in this case.
http://www.schneier.com/blog/archives/2005/11/sonys_drm_root...
Nobody is worried about the things they cannot see, and the things which are not directly harming them.
It behooves us to focus on the things people do see, so that we do a better job of eliminating the malware that is giving them tangible issues.
I'm not saying 'Flame is a non-issue, suspend all analysis of it by malware researchers!'. I am saying, that for most of us in the AV field this is a hand-to-hand combat type of industry and we don't have the time or resources to get all academic and hypothetical. We need to fix real infections on real machines, like yesterday!