Want to help family with a security problem? Don’t ask an AI for them — do it with them

The warning article — publish preview

charades.net · a warning, from the site

first-hand > relayed

Someone you love calls you with a security problem. A weird text, a scary popup, a charge they don’t recognize. You’re the one in the family who’s good with this, so the urge arrives immediately: I’ll ask my AI about it and call them back.

The urge is good. It comes from the best place there is — someone trusts you, and you want to be worth it. This article is about why that particular way of helping — you, alone, relaying their problem to an AI assistant — is the wrong tool for the job, and what to do instead. The person who runs this site responds to security incidents professionally, and this is the warning he would give a friend.

[ 01 ]An AI conversation is not a search you run for someone

A search engine hands back links and doesn’t care whether you like them. A modern AI assistant is different by design: it’s a conversation, and the system on the other side is built to produce answers it predicts you will find satisfying. Researchers call the failure mode sycophancy — the tendency of these tools to agree with your framing, mirror your assumptions, and tell you what you seem to want to hear. It is measured, it is widespread, and it matters more in security than almost anywhere else, because in security the comforting answer and the correct answer are often different answers.

Now add the relay. When you bring an AI someone else’s problem, the assumptions it mirrors back aren’t even the affected person’s — they’re yours, about a situation you haven’t seen.

[ 02 ]Security answers live in details you don’t have

When a professional works an incident, the first thing they want isn’t a summary — it’s the artifact. The exact message, the exact address it came from, the exact wording of the popup, what the screen says right now. An AI assistant working a security question is the same: it can only reason from what’s in front of it, and what’s in front of it is whatever survived the trip from their memory, through their phone call, through your retelling.

That trip is lossy even when both people are careful, motivated, and well-meaning — this isn’t a hunch, it’s one of the oldest findings in psychology. In classic “serial reproduction” experiments, retold accounts systematically drop peripheral details, exaggerate the dramatic ones, and reshape the rest to fit what the reteller already believes. Medicine has the same finding in its own language: when details go missing from a patient’s history, diagnostic accuracy degrades — reliably enough that it’s a studied error class. A security question relayed secondhand is a history taken secondhand. The critical detail that decides the answer — the one character that’s off in the address, the permission the app asked for — is exactly the kind of detail relays lose.

[ 03 ]The double translation problem

Here’s the quiet trap in the middle. Security has a lot of jargon, and an AI assistant genuinely is a good translator of it — when you’re speaking with it directly about your own situation. Ask it what a term on your own screen means and it can meet you where you are.

But the relay makes the translation run twice. Your relative explains their problem in their plain English. You re-explain it to the AI in yours. The AI now has to reconstruct the technical reality behind two layers of paraphrase — which means it has to assume. In a low-stakes question, assumptions are harmless. In a security question, an AI filling gaps with plausible assumptions produces answers that at best mislead and at worst cost real money or make things worse. And here’s the part worth being honest about: when that happens, the AI will get the blame — when the real fault was a process that fed it a story instead of a situation.

[ 04 ]“But my AI can search the web now”

It can, and that helps less than it seems here. A security conversation is rarely one question with one answer — done right, it’s a working session: ask, look at the screen, answer, ask again. The tools an assistant uses, like web search, inherit the quality of what you feed them. Give it a secondhand, detail-blurred description and it will search for the wrong thing — and come back confident about what it found.

You wouldn’t ask your aunt to run your web searches for you and read the results over the phone. This is that, with smoother delivery.

[ 05 ]Even a perfect relay breaks on the way back

Suppose you do everything right. You know the terminology, you asked sharp questions, the AI’s answer is solid, and you explain it carefully. There is still one step you cannot control: how the other person hears it. What they write down, what they skip because it sounded optional, what they were too embarrassed to say they didn’t understand. Help that has to survive a second trip through the telephone game arrives in worse shape than it left — and they act on what arrived, not on what you sent. People who study informal family tech support find that the helpers carry this weight already: the responsibility of being right for someone who trusts them, without the tools to be sure.

[ 06 ] · What to do instead: their device, their words

The fix isn’t a better relay technique. The fix is not relaying.

If someone you care about needs security help and an AI assistant is going to be part of it, do it with them, not for them. They should be at their own device, putting the questions to the assistant themselves, with you alongside — in the room if you can get there, or on a call with them sharing what is on their screen. Go to their house if that is what it takes. The rule is not about where you are standing. It is about whose hands are on the keyboard. Work the problem together — their details, their screen, their words, first-hand, with you there to keep the conversation honest and to translate in both directions live. That turns the problem around: the real artifact is in front of the AI, the assumptions get corrected the moment they appear, and nothing has to survive a retelling — in either direction.

That’s the whole warning. Nothing on this page makes anyone safe, and no AI conversation does either — first-hand or otherwise, the answers still need checking against the source: the bank’s own number, the store’s own listing, the company’s own site. But a first-hand conversation gives you a fighting chance of asking about the problem that actually exists. A relayed one never had it.

The posts on this site are built the same way this article recommends: every prompt is written to be used first-hand, by the person at the device — and we run them ourselves and publish what came back, including where they fell short.

Previous
Previous

What happens to a post before you read it

Next
Next

What we did to check these posts