A scoring API's owner asks which anti-extraction control still binds next quarter - what do you say?
answer
- rank by what the adversary can spread
- who pays besides the adversary?
- the control is read before it is faced
- attribution and time, not prevention
- decide the fidelity you accept
basics
~20 sNone is a boundary; you are picking prices. Per-key caps are amortised away by cheap identities, coarsening taxes your own bidders, and a distribution signal fades once imitated. Only identity friction raises an unspreadable cost.
solid answer
~50 sI would rank them by whether they raise a cost the adversary can spread. A per-call quota is spread across identities for the price of an account, so against a funded party it is worth close to nothing next quarter. Coarsening the returned score multiplies their reply count by a constant they absorb, while landing the same lost precision on buyers who pay us for exactly that resolution: a transfer from customers in exchange for a modest tax. A distribution signal buys attribution and time only, needs the identities joined, and decays once they draw product-like traffic. The one term that does not spread is the price of an identity, and that price is paid by our self-serve funnel, so it is a product call rather than a security setting. What I would ask the owner to decide is which fidelity of copy we are content to see in the world.
code
text · 9 linescontrol review - scoring api, current quarter
per-key rate limit ................ 1,000 calls / key / day [in place]
returned score .................... rounded to 2 decimals [in place]
extraction risk ................... MITIGATED
...
cost of one new self-serve identity ......... (not recorded)
replies needed for a usable copy ............ (not recorded)
can identities be joined to one actor? ...... (not recorded)
precision now returned to paying bidders .... (not recorded)go deeper
Recall that these controls raise an adversary's bill rather than closing a door, and that the same settings are felt by paying callers. Do not describe a rate limit as making extraction impossible.
Be able to say, for each control, which cost it raises and whether more accounts or more weeks make that cost go away. That test sorts the levers faster than any list of mechanisms.
Show you would present a control with both numbers attached - what it costs the adversary and what it costs customers - and that you would challenge a register entry that turns a divisor into the word mitigated.
Own the strategic call: on a function sold by the call, the question is which fidelity of copy you accept, how much product quality and signup conversion you will spend to raise a bill, and whether attribution was designed in before you needed it.
## The question being asked An owner of a paid relevance-scoring API wants to know what the anti-extraction controls are worth. Not what they are - what they will still be worth after an adversary has read them and repriced. That reframing is the whole answer, because every control on this surface is a price, and prices are repriced around. ## Rank by spreadability The single most useful sorting rule: does the control raise a cost the adversary can spread across more identities and more weeks, or one they cannot? **Per-call quotas - spreadable, therefore near zero.** A limit attached to a key is divided by funding more keys. Against a party willing to spend, it changes the identity count and nothing else. Its residual value is real but small: it prices out the unfunded and the careless, bounds accidental scraping, and produces a billing record. Its residual cost is not small - it is our own high-volume buyers who meet the ceiling first. **Output coarsening - spreadable, and it charges our customers.** Fewer bits per reply raises the replies needed for a given fidelity, which is a multiplier the adversary absorbs. The same lost precision reaches the buyer whose bid is computed from that score, and they cannot buy it back with volume. So this control is best described as a transfer: paying callers give up resolution so that an adversary's bill is multiplied by a constant. Whether that trade is worth making is an argument with two numbers in it, not a configuration change. **Distribution signals - the only informative one, and decaying.** Traffic that seeks coverage looks unlike traffic that follows demand, and that difference is a property of the query set rather than its size. It buys attribution and time rather than prevention, it exists only if identities can be joined into one actor, and it fades as soon as the adversary pays extra replies to draw product-like traffic. Worth having; worth stating with its expiry. **Identity friction - the term that does not spread, paid by the funnel.** Everything above is divided by the number of accounts. What is not divided is the cost of bringing one account into existence and the risk of accounts being linkable afterwards. That is where the adversary's unspreadable money sits. It is also where our growth sits, which makes it a product decision owned jointly - not a control a security team turns up on its own. ## What I would refuse to write down I would not sign a register entry reading *rate limited, extraction risk mitigated*. It records a divisor as a barrier. The direction of the claim matters: a quota that has never been exceeded tells us about the quota; a distribution monitor that has never alarmed tells us about our definition of normal; a coarsening change with no customer-side number tells us half of a trade. If the register needs a line, it should carry an estimate of what a usable copy costs to obtain at our published prices, beside what our controls currently cost paying customers. ## The decision I would actually put to the owner The function is sold by the call. While that is true, a sufficiently funded party can obtain a copy of it, and the levers available adjust how much they pay and how visible they are, not whether they can. So the decision is not *how do we stop this* but: - what fidelity of copy are we content to have loose, and does a copy at that fidelity actually take our revenue - or is our value in freshness, inventory access, integration and the data behind the model rather than in the function itself; - how much of our own product quality and signup conversion are we willing to spend to raise their bill; - do we want attribution when it happens, which is a design requirement on identity linkage and on retaining query shape, decided before an incident rather than during one. An accepted risk written down with its reasoning is worth more than a control whose only measurable effect is on our own customers. Where attribution after the fact matters commercially, that is a different lever with its own evidentiary questions, and it belongs in its own conversation rather than being folded into a rate-limit ticket. ## What next quarter looks like If the adversary is funded and patient, next quarter the quota is worth what it was worth this quarter - a divisor - and the distribution signal is worth somewhat less than today, because it is the one they have an incentive to buy their way around. Identity friction is the only line item whose value depends on a decision we can still make. Saying that plainly, with the customer-side cost attached to each option, is the answer the owner needs; ranking the controls without pricing what our own callers lose is the failure mode.
- The owner wants one number for the risk register. What do you give them?Not a status word. Two figures with an assumption each: the estimated cost of a usable copy at our published prices, including the identities needed to hold the calls, and what our current controls cost paying customers. A single word hides the fact that the entry describes a price, and prices move when the other side reprices.
- Sales wants self-serve signup with no payment instrument. What is your answer?Framed as a trade, not a veto: it drives the price of the only unspreadable term towards zero, and every other control we have is a divisor applied to that number. I would quantify the funnel gain against the identity supply it creates, and note that free accounts also remove the linkage that any attribution later depends on.
- When is the right answer simply to accept it?When the obtainable copy is materially worse than the product, when our value sits in freshness, inventory access, integration or the data behind the model rather than in the function, or when no plausible adversary is funded enough to run the campaign. Write the acceptance down with its reasoning; it ages better than a control that only taxes our own customers.
saying these in an interview costs you the question
- Records a quota as extraction risk mitigated
- Ranks controls without pricing what customers lose
- Assumes the adversary has not read the control
- Treats output coarsening as free to the product
- Promises a boundary where only prices exist