ITSECURITYWHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
Board › Why we never say you are safe

Why we never say you are safe

The one answer this site will not give you.

There are three verdicts here: affected, possibly affected, and not enough information. There is deliberately no "you are not affected".

The reason is asymmetry. A wrong "you are affected" costs you an afternoon checking something that turned out to be fine. A wrong "you are not affected" costs you the patch you did not apply, and you find out from whoever does your incident response.

We know what you typed into a form. We do not know your estate — the forgotten appliance, the contractor’s box, the version that was rolled back and never rolled forward again. Nothing that knows so little should be clearing anyone.

So when your version sits outside a vendor’s published affected range, we record nothing rather than recording safety. A vendor range can be incomplete, and it has been before.

This is enforced in software, not by editorial discretion. Any generated piece that tells a reader they are unaffected, safe, or need take no action is stopped before it publishes.