You must set one maximum credential validity for the whole estate — what evidence decides the number, and when does shortening stop paying?
answer
- evidence on both sides of the number
- detection record, or admit it is never
- the floor is measured, not chosen
- ceilings per class beat one figure
- the payoff flattens below hours
basics
~20 sTwo measurements decide it: how long a leak goes unnoticed here, and the longest holder that cannot obtain a fresh value mid-run. Shortening pays hugely from years to days to hours, then flattens — below that you trade availability for a narrow band.
solid answer
~40 sA defensible number rests on evidence rather than preference. The first measurement is how long a leaked copy has historically sat before anyone in this estate noticed; if you have never noticed one, the honest figure is never, and that argues for the shortest number the holders allow. The second is the tail of holding periods — the longest consumer that cannot obtain another value while it runs — which is the floor. Between the two, set ceilings per class rather than one figure, because a single number is decided by the worst holder. And say where it stops paying: the gain from four years to one day is enormous, one day to one hour is real, one hour to one minute is mostly availability spent against a path the hour already covered.
go deeper
The takeaway is that a validity figure is argued for, not chosen by taste: someone has to say what it protects against and what in the estate cannot live with it.
Be able to state both measurements — how long a leak goes unnoticed, and the longest holder that cannot obtain a fresh value mid-run — and why the second one is the floor.
Show that you would gather the two figures before proposing one, and that you can name the first three holders in your own estate that would break, with their holding periods.
This is the judgment call: ceilings per class, an exception register with owners and dates, an explicit stopping point for shortening, and an honest account of the availability and issuing-load cost you are buying the reduction with.
"Make credentials short-lived" is a preference until someone has to write a figure into a standard that other teams are held to. At that point the number needs evidence on both sides, and a lead is expected to name the cost as well as the benefit. ## Two measurements, not a preference **How long a leak goes unnoticed here.** The validity period bounds exactly the exposure that detection never reaches, so the number it must be argued against is the estate's own detection record: when a copy of a credential has escaped, how long did it sit before anyone acted? Most organisations discover they have no such record, because they have never identified a leaked credential at all. That is not a missing measurement — it *is* the measurement, and its value is **never**. An estate with no detection history should reason as though every escaped copy is permanent until it expires, which pushes the number down to whatever the holders will bear. **The longest holder that cannot re-acquire.** The floor under any estate-wide figure is the longest unbroken period some consumer keeps one value with no way to obtain another — a job that reads at the start and runs for hours, a pool whose connections authenticate once and live for days, a process that reads at boot and holds until redeployment. This is the number that decides whether your standard is a setting or a change programme. ## Why one number is the wrong shape A single estate-wide figure is always decided by the worst holder, which means the strongest case for shortening — human access, and the services that can already re-fetch freely — gets dragged up to the level of the one consumer nobody has time to change. Ceilings per class avoid that: | class | what decides its ceiling | |---|---| | people reaching production directly | the length of a task, not a shift or a day | | workloads that can obtain a value freely | the cost of obtaining one, not the work | | holders that read once and keep it | their holding period, until they are changed | | the named exceptions | an owner and a date, reviewed, not permanent | The exception register is the part that decides whether the standard survives contact. An exception with an owner and a review date is a plan; an exception list with neither is the real standard, written by whoever asked last. ## Where the payoff flattens Shortening is not linear in value, and pretending it is loses credibility fast: 1. **Years to days** removes an entire class of exposure — the copy in an archive, a backup, an old image, a former contractor's machine — all of which go inert with nobody doing anything. 2. **Days to hours** still buys a lot: it closes the copy found by somebody who was not looking for it, days after it appeared. 3. **Hours to minutes** buys a narrow band. Against a copy that surfaces somewhere automated eyes are watching and is used within seconds, an hour was never the binding constraint and a minute is not either. Against the slow paths, the hour already handled them. So the honest claim is that most of the value is in the first two or three orders of magnitude, and below that you are spending availability on a path the number does not control. That is where a lead should redirect the argument: to what the credential *reaches* and to who can obtain one, rather than to another decimal place on the lifetime. ## What you are buying the reduction with Every step down moves work into the acquisition path. A holder that used to read a value once now depends on obtaining one repeatedly, so the issuing side becomes a live dependency of the workload rather than a start-up detail, and somebody has to decide what a consumer does when it cannot get a value. The load on the issuing side rises with the same factor as the shortening. Both of those are their own subjects with their own owners; the point for the person setting the number is that they are real costs, they arrive immediately, and a standard that does not acknowledge them will be blamed for the first outage that follows. A defensible answer therefore has four parts: the detection figure (even when it is *never*), the measured floor, ceilings by class with an exception register that has owners and dates, and an explicit statement of where you stopped shortening and why.
- You have never detected a leaked credential. What detection figure do you use?Never — and say it out loud rather than substituting an industry number. An estate with no detection history has no measured window, so the validity is the only bound that exists on an escaped copy. That argues for the shortest figure the holders will bear, and it makes the detection gap itself a finding worth naming beside the number.
- Why set ceilings per class instead of one estate-wide figure?Because one figure is decided by the worst holder, so the consumers with the strongest case for minutes get dragged up to the level of the one job nobody can change this quarter. Classes let human access and re-fetching services move immediately, while the long holders sit in an exception register with an owner and a date rather than silently setting everyone's number.
- What does shortening cost that the security case usually leaves out?Every holder now depends on obtaining a value repeatedly rather than once, so the issuing path becomes a live dependency of the workload and its load rises by roughly the same factor as the shortening. Somebody also has to decide what a consumer does when it cannot get a value. Those are real costs and they arrive on the first day.
saying these in an interview costs you the question
- Picks a round number and calls it a standard.
- Assumes shorter is always better, with no floor and no price.
- Quotes an external expectation as the whole reason for the number.
- Sets one estate-wide figure decided by the slowest consumer.
- Ignores that every holder now depends on obtaining a value repeatedly.