skip to content

Your control document claims a face gate cannot be attacked because it returns only accept or reject — what do you tell the auditor?

level: principalimportance: nice to knowfreq 26%

answer

  1. separate the design from the sentence written about it
  2. expense is claimable, infeasibility is not
  3. read what the evidence line actually establishes
  4. the surviving family pays in decisions
  5. state a residual instead of asserting it away

basics

~20 s

Say the control is real but the claim is wrong. A bare decision removes the attacks that need numbers and multiplies the calls the rest need; it does not make an accepted adversarial input infeasible. Restate it as a cost control, name the limit that binds the survivor, and test that.

solid answer

~50 s

Separate what was built from what was written. What was built is worthwhile: withholding scores removes the attack family that estimates a direction by differencing numbers, and it multiplies the live calls the remaining family needs. What was written asserts infeasibility, and the reply schema does not support that, because a search that consumes only the returned decision needs no numbers — it starts from an input the gate already accepts and shrinks the difference while the accept holds. Note also what the evidence line supports: a response-schema review establishes what the endpoint returns and nothing about how many decisions an adversary can consume. So my answer to the auditor is that the control stands as a cost control, the infeasibility sentence is withdrawn, the compensating limit is the attempt budget per subject, and we owe them a tested number for it. Never assert to someone who can compel an answer a property nobody has measured.

code

text · 9 lines
text
Control:   AUTH-14  Verification endpoint response minimisation
Statement: "The endpoint returns only ACCEPT or REJECT. No score,
            margin, ranking or diagnostic detail is disclosed."
Assertion: "Therefore adversarial input search against the gate is
            not feasible."
Evidence:  Response-schema review (2 pages), signed by service owner.
Testing:   None recorded.
Residual:  None stated.
...

go deeper

for a junior

Know that withholding scores is a cost measure, so a document saying a label-only endpoint cannot be attacked is overstating what the design achieves.

for a middle

Be able to explain the mechanism behind the correction: a search that consumes only the returned decision never needed the numbers that were removed.

for a senior

Show that you check evidence against assertion — a response-schema review supports statements about fields returned, not about how many decisions an adversary can consume.

for a principal

Own the call: withdraw the untested claim, restate the control in the currency it operates in, fund the measurement, record a residual, and refuse a fix that only coarsens the reply further.

## The two things on the table An auditor is reading a control statement and asking whether it is true. There are two separable objects: a **design decision** (the endpoint returns a bare decision) and a **claim** written about it ("therefore adversarial input search is not feasible"). A good answer keeps them apart, because the design decision is defensible and the claim is not, and conceding the claim does not require conceding the design. ## Why the claim fails Query-only attacks split into a family that needs numeric replies and a family that does not. The first estimates a search direction by probing and differencing returned scores; withholding scores removes it outright. The second consumes only the returned decision: it begins from an input the gate already accepts and reduces the difference toward the input the adversary wants accepted, keeping the changes under which the answer stays `accept`. One bit per call is enough to steer, so the second family survives every level of coarsening down to the answer the product exists to give. You cannot withhold accept-versus-reject from a verification gate; that *is* the gate. So the mechanism supports a statement about **expense** and not a statement about **possibility**. Writing the second where only the first is warranted is the defect, and it is a defect of assurance language rather than of engineering. ## Reading the evidence line The second failure is usually visible in the control's own evidence. A response-schema review establishes which fields leave the service. It establishes nothing about how many decisions an adversary can consume, what event the attempt counter increments on, whether attempts reset on a cooldown, or whether the same subject can be approached through more than one identity or channel. A control whose asserted property is about attacker effort, and whose evidence is about response fields, has no evidence for its assertion. That mismatch is the thing to point at, because it is checkable and it is not a matter of opinion. ## What to say, in order 1. **Concede precisely.** The claim of infeasibility is not supported and is withdrawn. Say it plainly; hedging it in front of someone who can compel an answer converts a documentation defect into a credibility problem. 2. **Keep the control, restated.** The reply schema is retained as a cost control, and describe what it buys: one attack family removed, and a substantially larger number of live calls for the family that remains. 3. **Name the limit that now binds.** The surviving family pays in decisions, so the compensating control is the attempt budget per subject — counting accepted decisions as well as failures, scoped across identities, sessions and channels rather than to one account, with cooldowns described as a rate rather than a ceiling. 4. **Commit to a number and a date.** Two figures make this auditable: how many decisions the deployment will actually serve one adversary before anything stops them, and how many decisions a label-only walk needs against this gate to reach a difference that matters. Until both exist, the correct status is *untested*, not *sufficient*. 5. **Say what the residual is.** An auditor can accept a residual risk that is stated. They cannot accept one that was asserted away. ## The organisational judgment underneath The reason this lands at a lead's desk rather than an engineer's is that the fix is not code. Someone must decide that the organisation will not publish infeasibility claims it has not tested — including in vendor answers, security questionnaires and customer-facing summaries where the same sentence tends to be reused — and must accept the cost of that decision: an auditable residual where there used to be a clean assertion, and a testing commitment somebody has to fund. There is also a live temptation to answer with another coarsening ("we will also remove the detail from the error message"), which is not responsive: it is the same class of change, and the surviving family already needs nothing but the decision. Recognising a non-responsive fix and saying so is part of the call. ## What not to do Do not argue that the attack is expensive and therefore the sentence is close enough — expense is what you are now claiming, so claim it. Do not offer a robustness figure from a vendor deck as substitute evidence; a number produced by an attack somebody else ran against a different deployment says nothing about your attempt budget. And do not let the withdrawal of one sentence widen into a claim that the gate is broken: the design is sound, the wording was not. ## In an interview The examiner wants to see you separate mechanism from claim, identify the evidence mismatch, restate the control in the currency it actually operates in, and finish with what you would commit to measure. A confident, specific concession plus a testable replacement is the whole answer.

  • What single piece of evidence moves that control from assertion to claim?
    A measured decision count: how many decisions the deployment serves one adversary before anything stops them, counted per subject across identities and channels and including accepted calls, set beside how many a label-only walk needs against this gate. A response-schema review cannot substitute for it.
  • The owner offers to strip detail from the error message instead — is that responsive?
    No. It is the same class of change as removing the scores, and the family that survives already consumes nothing but the accept-or-reject answer. It may be worth doing for other reasons, but it does not address the finding, and accepting it as a fix would repeat the original error.
  • How would you word the control so it is defensible?
    As a cost control with a scope: state which attack family the reply schema removes, state that the remaining family is bounded by attempt budget rather than by reply content, cite the tested decision figures and the counting rule behind them, and record the residual. No sentence about infeasibility.

saying these in an interview costs you the question

  • Asserts infeasibility that nobody has tested
  • Offers a response-schema review as attack-surface evidence
  • Calls reply coarsening a preventive control
  • Answers a compelled question with marketing language
  • Accepts another coarsening as a responsive fix

context