If you’re right, that’s still (comparatively) a lot of English to communicate very few bits of information. If I cared, I’d honestly be a bit miffed that they made me spend a minute on this shaggy-dog post/ad chimera instead of putting a single sentence in the announcements section of their front page or dashboard (which is a section that needs to exist if it doesn’t already). Like
2023-07-25: Microcode patch for [Zenbleed](https://lock.cmpxchg8b.com/zenbleed.html) ([CVE-2023-20593](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-20593)) now rolling out across fleet, expected complete 2023-mm-dd, no evidence of exploitation so far.
Was that so hard? TFA doesn’t even give an estimated completion date, so that’s actually more info than the original! (If they don’t have one yet, that’s OK too of course.)
If the post actually did a better job than other sources of explaining the problem to at least some potential audience, I would’ve welcomed it, and in fact I’m probably crabby exactly because I’ve come to expect good and frank technical explanations from the Cloudflare blog (whatever I may think of their business). But this one is just meh, with a sprinkling of bleh from the forced cheer in the title.
(Sez I who has just spent 200 words’ worth of English just to complain.)
Can you elaborate? I may certainly have missed a potential target audience, but I can’t really think of one that would be more confused / farther from the truth after reading my headlinese than before, which is what I assume you meant by negative information.
When every tech news site puts the vulnerability in headlines, it's going to have a lot of visibility and many of Cloudflare's customers are going to ask them about it (regardless of whether the attention is warranted or not).
Comments
To reassure customers?
If you’re right, that’s still (comparatively) a lot of English to communicate very few bits of information. If I cared, I’d honestly be a bit miffed that they made me spend a minute on this shaggy-dog post/ad chimera instead of putting a single sentence in the announcements section of their front page or dashboard (which is a section that needs to exist if it doesn’t already). Like
Was that so hard? TFA doesn’t even give an estimated completion date, so that’s actually more info than the original! (If they don’t have one yet, that’s OK too of course.)If the post actually did a better job than other sources of explaining the problem to at least some potential audience, I would’ve welcomed it, and in fact I’m probably crabby exactly because I’ve come to expect good and frank technical explanations from the Cloudflare blog (whatever I may think of their business). But this one is just meh, with a sprinkling of bleh from the forced cheer in the title.
(Sez I who has just spent 200 words’ worth of English just to complain.)
Because your suggestion provides less value and near zero or actually probably negative information to the target audience.
Can you elaborate? I may certainly have missed a potential target audience, but I can’t really think of one that would be more confused / farther from the truth after reading my headlinese than before, which is what I assume you meant by negative information.
I figured the default assumption was these vendors kept updated with security patches.
Do we really need a blog post every-time they run apt/yum update?
When every tech news site puts the vulnerability in headlines, it's going to have a lot of visibility and many of Cloudflare's customers are going to ask them about it (regardless of whether the attention is warranted or not).
That still doesn't stop people from asking about log4j way over a year after the entire fiasco went down...
That's a damn big assume when you have compliance to worry about.