skip to content

Your store accepts platform-signed identity documents up to an hour old to survive clock skew — what has that handed an attacker?

level: seniorimportance: should knowfreq 40%

answer

  1. nothing to revoke, only to expire
  2. age is the only bound
  3. a copy works for the whole window
  4. drift is seconds, not an hour
  5. fix the clocks, not the window

basics

~20 s

An hour of impersonation from any copy that escapes. A widened window turns a short-lived document back into a reusable credential, and nothing can recall it — the store simply accepts it until it ages out.

solid answer

~40 s

The document is a bearer artifact: whoever holds it can present it, and its only real bound is age, because there is nothing stored for anyone to revoke. A five-minute window means a copy that escapes into a crash dump, an error report, an outbound request or another process on the host is worthless within minutes; an hour-wide window turns the same copy into most of an hour of calling the store as that workload. Widening also fixes the wrong problem — clock drift is a matter of seconds, so a seconds-to-minutes allowance covers it and an hour covers something else entirely. Measure the drift, set the allowance just above it, alert on drift as a fault, and have the workload request a fresh document per fetch rather than holding one.

code

pseudocode · 11 lines
pseudocode
// what the freshness check is, and what the allowance costs

documentLifetime = 300 seconds     // set by the issuing platform
skewAllowance    = 120 seconds     // absorbs observed clock drift

accept if now <= document.notAfter + skewAllowance
      and document.issuedAt <= now + skewAllowance

// usable life of a copied document = documentLifetime + skewAllowance
//    300 +  120 =  420 seconds   (a measured, seconds-scale allowance)
//    300 + 3600 = 3900 seconds   (the "just allow an hour of skew" setting)

go deeper

for a junior

Recall that these documents expire quickly on purpose, and that a longer acceptance window means a stolen copy keeps working for longer.

for a middle

Explain that the allowance adds directly to every document's usable life, and that clock drift is a seconds-scale fault rather than an hour-scale one.

for a senior

Show the operating response: measure the drift, alert on it, keep the recipient check strict, request a document per fetch, and narrow the identity's reach while the window stays wide.

for a principal

The angle to bring is the asymmetry — a credential nobody can withdraw changes what your incident response can promise, and that belongs in the decision about how much of the estate moves to attested identity.

## Why the document has an expiry at all A platform-signed identity document is presented, not compared. Nothing about it is secret in structure, and the store has no record of having issued it — the platform minted it and handed it straight to the workload. That has one consequence that shapes everything else: **the store cannot recall it**. There is no stored row to delete, no issued reference an operator can act on. Once the signature exists, the document is acceptable until its own freshness fields say otherwise. So the validity window is not a detail. It is the only bound on a credential that anyone holding a copy can use. ## Where a copy comes from The design removed the stored secret, not the possibility of a copy. Documents pass through places that keep things: - a crash dump or a memory image taken for debugging; - an error report or a diagnostic bundle that captured outbound request details; - a proxy, a tracing layer or a request recorder sitting in front of the store; - another process on the same host, reading what the workload holds; - a service the workload also talks to, if the recipient field is not being checked. Each of these is a routine part of operating a system. None requires an attacker to have broken anything cryptographic. ## The arithmetic of a widened window The usable life of an escaped copy is the document's lifetime plus the store's drift allowance, less however much already elapsed. With a five-minute lifetime: 1. A two-minute allowance gives a worst case of **seven minutes** of impersonation. 2. A one-hour allowance gives a worst case of **sixty-five minutes** — a factor of roughly nine, bought to paper over a fault of seconds. 3. Restoring a two-minute allowance takes the exposure straight back down, without touching anything else in the design. The numbers matter because the widening is usually argued for on availability grounds, and the availability problem it solves is almost always smaller than it looks: rejections cluster on one badly synchronised host, not across the fleet. ## The knobs, and what each costs | Knob | What it buys | What it costs | |---|---|---| | Shorter document lifetime | A copy is worthless sooner | More mint requests; less tolerance of a slow caller | | Wider drift allowance | Fewer rejections from misaligned clocks | Every document's usable life grows by the allowance | | Strict recipient check | A copy is useless at any other service | Nothing meaningful — this is the cheap one | | Fresh document per fetch | No document sits around being reusable | A mint call on the request path | | Reusing one document per process | Fewer mint calls | A held credential again, which is what the design removed | ## What to do instead of widening - **Fix the clocks.** Drift is a host fault. Treat a rejection spike as a monitoring signal about time synchronisation, not as a prompt to loosen a check. - **Measure before you set.** Size the allowance just above the drift you actually observe, in seconds, rather than choosing a comfortable round number. - **Keep the recipient check strict.** It costs nothing and it is what makes a copy useless anywhere but your store. - **Request per fetch.** Documents are cheap to mint precisely so that nothing needs to hold one. A workload that obtains one document and reuses it for an hour has rebuilt a stored credential with extra steps. - **Reduce the reach while the window is wide.** If a broad allowance genuinely cannot be narrowed today, the compensating control is what the identity is allowed to read, because that is the only other bound available. ## The asymmetry worth naming in an interview With a stored credential, the remedies are direct: replace the value, or make the old one stop working. With a platform-signed document, neither is available. You cannot replace it — the platform will mint another for anyone entitled to one. You cannot withdraw it — the store never issued it. The remedies are all indirect: wait out the window, stop trusting that subject at the store, or change what the subject may read. That asymmetry is the whole argument for keeping the window narrow, and it is why an hour-wide acceptance window is a materially different security posture from a five-minute one even though both are described as short-lived.

  • The clocks really are drifting by minutes and you cannot fix them today. What do you do?
    Measure the drift rather than guessing, set the allowance just above what you measured, and raise drift as a fault with an alert so it is visible as a defect rather than absorbed as configuration. While the window is wider than you want, narrow what that identity is allowed to read — that is the only other bound available, since the document itself cannot be recalled.
  • Why can you not simply revoke a document that has leaked?
    Nothing was stored to revoke. The platform signed it and handed it to the workload; your store learns of its existence only when it is presented. The available remedies are all indirect — wait out the window, stop trusting that subject at the store, or reduce what the subject may read. That is exactly why the window is the control.

saying these in an interview costs you the question

  • Widens the freshness window to silence clock-skew rejections.
  • Thinks a short-lived document cannot be replayed within its window.
  • Treats the document as revocable once it has been signed.
  • Assumes drift of an hour is normal and must be absorbed.
  • Holds one document for the life of the process and reuses it.