Shostack + Friends Blog


It's Not Working!

Help me help you...

As we launched the threat modeling manifesto, we ran into some trouble with TLS. Some of you even reported those troubles, by saying "it's not working."


That's so helpful.

Sarcasm aside, there's a basic form to a helpful bug report: "I did A, and observed B." If you want to make it really useful, add "I expected C," or even "and the impact is D."

Let me compare and contrast with an example:

"I clicked on the link I see in your post at (URL) in Chrome 86 on MacOS big sur, and I get a message "Host not found."

Again, to compare and contrast: "I tried to follow the link..." (How? Which link?)