DEV Community

StarkMan
StarkMan

Posted on

A Date Filter Is Not an Install Date: Reading Time-Bounded Exposure Queries

A Date Filter Is Not an Install Date: Reading Time-Bounded Exposure Queries

The NCSC summary of the May 2020 US sanction describes a change that took effect in 2020. Relating an exposure measurement to that date requires care about what a time filter means.

Bounding the observation

On 4 October 2026, app="Huawei" returned 18,927,766 matches and app="Huawei" && after="2020-05-15" returned 17,653,722.
| Query | Scope | Matches observed |
| --- | --- | ---: |
| app="Huawei" | All records | 18,927,766 |
| app="Huawei" && after="2020-05-15" | Records after a date | 17,653,722 |

What after refers to

A date filter in a scanning platform applies to the last time the record was updated in that platform, not to when a device was installed, purchased or deployed. A router installed in 2015 and re-observed in 2024 will sit after a 2020 cut-off.
That is why the large majority of matches fall after the date. The number describes observation recency, not procurement history.

The honest use of a time filter

The filter is useful for narrowing to records that were seen or refreshed recently, which helps when you want a current picture rather than a historical one. It cannot be used to claim that a device appeared because of a specific 2020 policy change.

Practical next steps

  1. State that a date filter refers to record recency.
  2. Use date filters to select fresh observations, not to date installations.
  3. Never attribute a device's presence to a policy event based on a date filter.
  4. Keep the unfiltered and filtered counts side by side.

Limitations

Record timestamps depend on the platform's own observation schedule, which may be uneven by region and network.

References

Top comments (0)