Elektrine lite

← Feed

@davidism@mas.to

Post #572478

2026-02-24 00:36 UTC

Most security reports could be a couple sentences and a small code snippet, and would be better for it. I hate that every report is written as if it were a blog post about their finding and how it's the greatest disaster of all time. Write as if you're having a dialog with a knowledgeable maintainer, wait for questions to elaborate if needed. LLMs have not made this better either.

Replies (3)

  • @sethmlarson@mastodon.social 2026-02-24 01:33

    @davidism Ugh, yeah. This and another comment I saw from @gpshead on the pip-tools AI policy has inspired me to write a tiny blog post about this.

    Open ##1256917

  • @badsamurai@infosec.exchange 2026-02-24 02:12

    @davidism I wish they were just a set of OCSF objects. But no, we get C2s and common cloud infrastructure mixed into a crappy list of iocs at the bottom

    Open ##1256919

  • @pathunstrom@ngmx.com 2026-02-24 03:33

    @davidism I think I've explained it to newbies as * What did you do? * What happened? * What did you expect to happen? Like, if I got the answer to all three questions every time I got a report, I could at least determine help/bug/security quickly.

    Open ##1256920