Examines how security scanner vendors measure accuracy through precision and recall metrics, arguing that the F1 score, which weighs both metrics equally, reveals whether scanners truly balance finding real vulnerabilities against reducing false positives. A scanner can lower its false positive count by simply flagging fewer things, but this means real vulnerabilities pass through undetected.