A pipeline credential was found on a public page today but posted three weeks ago — what does that interval force you to assume?
answer
- two timestamps, not one
- start the clock at exposure
- unobserved is not the same as unused
- retention may end mid-window
- assume use for every right carried
basics
~20 sTreat the whole interval as unobserved use: assume the credential was copied by strangers throughout it, and scope the response to every right it carried for three weeks, not to the moment you found it.
solid answer
~40 sThe gap between when the value became public and when you found it is unobserved time, and nothing in it is evidence of safety. Work from the exposure date, not the discovery date: assume the value was copied by parties you will never identify and was usable for every right it carried across the whole window. Two records bound what you can say — the store's record of who fetched the value, and the counterparty's record of calls made with it — and either may not reach back three weeks. Silence in a record that only starts two weeks ago is silence about two weeks, not proof of non-use. The interval also sets what you re-examine: anything that credential could have changed in three weeks is now in question.
code
pseudocode · 17 linesexposedAt = day 1 // the page went public
discoveredAt = day 22 // someone told us
storeRecordFrom = day 8 // oldest read event the store still holds
partnerRecordFrom = day 15 // oldest call the counterparty still holds
firstRecord = min(storeRecordFrom, partnerRecordFrom) // day 8
bothRecords = max(storeRecordFrom, partnerRecordFrom) // day 15
blind = exposedAt .. firstRecord // days 1-8: nothing can speak for it
oneSided = firstRecord .. bothRecords // days 8-15: one side only
covered = bothRecords .. discoveredAt // days 15-22: both sides
for window in [blind, oneSided]:
assumeUsed(everyRightCarriedBy(credential), during = window)
report(evidenceOfUse = onlyFrom(covered),
assumedUse = blind + oneSided)go deeper
Know that the exposure clock starts when the value went public, not when someone noticed. The size of the problem comes from that interval, not from how fast you reacted to the news.
Explain why an empty access record over part of the window is far weaker evidence than it looks: finite retention, one record per side, and a stolen credential that authenticates successfully rather than failing.
Show how you bound the unobserved window with the records you actually have, and how you state the part neither side covers without either overclaiming use or implying safety.
Decide what the estate should be able to prove about an interval like this at all, and weigh what shortening time-to-discovery is worth against the cost of keeping more of the record for longer.
A credential exposure carries two timestamps, and treating them as one is the most expensive mistake available in the first ten minutes of a response. ## The two timestamps **Exposure time** is when the value became readable by people outside your control: when the page was published, when the archive was opened, when the file was shared with an audience nobody vetted. **Discovery time** is when you found out. The interval between them is the **detection gap**. On a credential that stayed valid throughout, that interval is not a delay in your response — it is a stretch of the credential's working life during which it was valid and public at the same time. The reframing does real work. A response written from discovery time asks *what has happened since we found it*, a question about the last few hours that is almost always reassuring. A response written from exposure time asks *what could have been done with this value over three weeks*, which is the question that actually sizes the problem. ## Absence of a record is not absence of use The instinct at 2am is to open the access record, see nothing unusual, and downgrade. Three separate things break that inference: - **Retention is finite.** Records are kept for whatever window was configured long before tonight, and designs differ on whether reads are recorded at all. If the store holds read events for fourteen days and the value has been public for twenty-one, its silence covers fourteen days and says nothing about the other seven. - **Each record sees one side.** The store's record shows the value being fetched out of the store. Someone reading it off a public page never touches your store, so their use leaves nothing there however long the retention. - **A stolen credential succeeds.** There is no failed authentication to notice. Use by a stranger looks, at the level of the record, like use by your own job — same credential, same rights, often similar calls. The honest statement after reading the records is therefore compound: *no recorded use in the window the records cover, and no visibility at all before that*. The second half is the half people drop. ## Dividing the interval Split the gap by what can speak for each part of it: | Part of the interval | Covered by | What you may claim | |---|---|---| | Before either record begins | Nothing | Nothing — assume use | | Covered by one record only | That side alone | Absence of use on that side | | Covered by both records | Store and counterparty | Absence of recorded use on both sides | The last row is the only one where "we see no evidence of use" is a meaningful sentence, and even there it is bounded by what each side chose to keep. ## The clock may start earlier still The posting is where the value surfaced, not necessarily where it left. The copy had to leave a system of yours first, and it may have been in circulation — in a shared folder, on an unmanaged machine, in someone's message history — long before it reached a page you can see. Two cheap signals bound that: the **value version**, because if the credential was changed on a known date and the exposed value is the pre-change one, the copy is at least that old; and whatever else appeared beside it, because a set of values that only ever sat together in one place dates the copy to when that place last held them. Where both are silent, the honest start of the interval is *unknown, and no later than the posting*. ## What the interval forces 1. **Assume the value was copied.** Not that it was used — you cannot know that — but that copies exist beyond your reach and will not disappear when the page does. 2. **Scope to rights, across the whole window.** Whatever the credential was entitled to do, treat as available to a stranger for the full interval, not for the minutes since discovery. 3. **Re-examine what those rights could have changed during it.** If the credential could submit, write or redirect, the objects it could touch need checking over the interval, not just checking now. 4. **Record the blind window as a finding.** The part of the gap no record reaches is a property of the estate, not a detail of tonight, and it will be exactly as wide next time. ## What the interval does not do A short gap is good news and not an exemption. Finding a value within minutes narrows the likely window of use, but the *reach* of the credential is a property of the rights it carried, not of how long it sat in public, so the scoping work is unchanged. A long gap does not by itself prove use occurred either; asserting use without evidence misleads a counterparty as badly as denying it. The defensible position is the narrow one: here is the interval, here is the part we can see, here is the part nobody can, and here is what we are assuming about it.
- The counterparty's usage record covers only the last seven days of a three-week exposure. What can you honestly say about the other fourteen?Nothing from that record. You can say the credential was valid and publicly readable for fourteen days you cannot see, and that no evidence of use exists for them because no evidence of any kind exists for them. Treat those days as use you cannot rule out and say so plainly to whoever decides the response; a shorter record is not a cleaner one.
- Does a short gap — found within minutes of posting — remove the need to scope what the credential reached?No. It narrows the likely window of use, which is genuinely worth a lot, but what the value could reach is set by the rights it carried, not by how long it was public. Minutes are enough for an automated collector, so the rights inventory is still owed. The short gap mostly improves how much of the window your records can actually speak for.
- Can you ever move the exposure timestamp earlier than the posting?Often, yes. If the exposed value is one version behind the value in the store, the copy was taken before that change, which pins it earlier than the page. Whatever appeared beside it helps too: a group of values that only ever sat together in one file dates the copy to when that file last held them. Absent both, treat the start as unknown and no later than the posting.
saying these in an interview costs you the question
- No unusual reads were recorded, so it was never used.
- The clock starts when we were told about the page.
- Nobody would find a value on a page nobody links to.
- The record keeps thirty days, so it covers everything.
- Once a new value is in place, the three weeks stop mattering.