Every few years, security vendors entice us with "next generation" security products with 0day detection and we must decide if this product will be our salvation or it's more snake oil full of empty promises. Basic theorems of computer science mathematically guarantee that many of the claims made by vendors are false without certain allowances, but that doesn't mean that the products are useless. Take a walk through the history of exploitation and computer science to learn how to ask the questions that will allow you to see if the vendor's claims can be achieved in your organization or whether you're being sold a bill of goods.