skip to content

A script produced a random 40-character warehouse password; why is that credential still static, not generated?

level: middleimportance: should knowfreq 52%

answer

  1. not about the characters
  2. count the holders, not the entropy
  3. who creates it, and when
  4. a script is still one value
  5. per-consumer issuance is the test

basics

~20 s

Static and generated describe how many consumers hold one value, not how the characters were produced. A value read by everybody is static however random it is; a generated one is created per consumer that asks.

solid answer

~40 s

The two words classify **distribution**, not entropy. Randomness buys resistance to guessing; it does nothing about the fact that the same forty characters are read by forty analysts and six jobs, that every holder has an identical copy, and that there is exactly one thing to withdraw for all of them. A credential is generated when the accepting system creates a distinct account for each consumer at the moment it asks, and can destroy that one again. So the test is not "who typed it" or "how long is it" but "does a second consumer asking get a second, separate credential?" If the answer is no, it is static — whether it lives in a settings file, in a store, or in a script's output.

go deeper

for a junior

Remember the one-line test: a value everybody reads is static, however random it looks. Generated means each consumer gets its own.

for a middle

Explain why entropy is the wrong axis: randomness resists guessing, while static against generated is about how many consumers hold one value and whether one can be withdrawn alone.

for a senior

Push the point where teams stop thinking: calling values 'generated' because a script produced them closes the review before anyone asks whether the accepting system can create and drop accounts at all.

for a principal

Be precise in a standard you write for other teams. A definition that says 'generate strong credentials' will be satisfied by a random string in a settings file; one that says 'per consumer, created and destroyable on request' will not.

## What the two words classify **Static** and **generated** are not grades of quality. They classify where a credential comes from and how many consumers end up holding one value. - A **static credential** exists once. Somebody — or something — produced it, it was written down, and every consumer that needs access reads the same characters. Forty analysts and six scheduled jobs holding identical text is one static credential with forty-six holders. - A **generated credential** is created by the accepting system at the moment a consumer asks, for that consumer alone, and can be destroyed again without touching anybody else. A script producing forty random characters affects only the first half of the first bullet: it changed *who produced the value*. It did not change that the value exists once, that it is stored once, and that everyone reads that one copy. ## Why entropy is the wrong axis Entropy answers one question: how hard is this value to guess from the outside? That is a real property and worth having — a short, memorable shared password is worse than a long random one against an attacker trying values at the door. But it answers nothing about the properties this distinction is actually about: - **How many copies of the value exist.** Randomness does not reduce the count. - **Whether one holder can be cut off alone.** With one shared value there is one thing to withdraw, and withdrawing it affects every holder at once. - **Whether the accepting system knows the consumers apart.** Forty-six holders presenting identical characters arrive as one identity, however unguessable those characters are. - **What happens when a copy escapes.** A copy of a 40-character value works exactly as well as a copy of an 8-character one. That is why "we generate strong passwords" is not an answer to "are your credentials static or generated", and an interviewer will usually follow up precisely there. ## The test, in one line Ask: **does a second consumer, asking independently, receive a second and separate credential?** | Situation | Static or generated | Why | |---|---|---| | One random value in a settings file, read by all | static | one value, many holders | | The same value moved into a secret store | static | the resting place changed, the distribution did not | | A fresh random value per environment, created by hand | static (several of them) | still fixed values with multiple holders each; the count per value simply fell | | The accepting system creates an account per consumer on request | generated | each request produces a separate, destroyable identity | The third row is worth dwelling on, because it is where honest teams land. Splitting one shared value into several by hand genuinely reduces how many consumers share each one. It is an improvement and it is not generation: nothing can create another on request, and nothing can destroy one without a human doing it. ## Where the confusion does real harm The cost of believing that random means generated is that it closes the question. A team says "our credentials are generated", the review moves on, and nobody asks the questions that actually matter for this estate: whether the warehouse can create and drop accounts at all, whether there is a definition the rights come from, whether anything would drop an account after its consumer was gone. Those are the questions a real move to per-consumer credentials has to answer, and the word "generated" used loosely is what stops them being asked. A second, quieter harm: the belief tends to travel with "so it does not need to be inventoried", because a value a machine produced feels less like a thing somebody owns. It is exactly as much a thing somebody owns. If forty-six consumers read it, forty-six consumers hold it, and somebody has to be able to say who they are. ## Saying it well in an interview The compact form is: *static and generated are about distribution, not about the characters.* One value everybody reads is static whether a person chose it, a script produced it, or a store is holding it. It becomes generated only when the system that accepts the credential can mint a distinct one per consumer and destroy it again — which is a property of that system, not of the value's randomness.

  • Does moving that shared value out of a settings file and into a secret store make it generated?
    No. It changes where the value rests and who can fetch it, which is worth doing on its own terms. It does not change that one set of characters is read by every consumer, that there is a single thing to withdraw for all of them, or that the warehouse still sees one identity connecting. Distribution is untouched.
  • Two teams are each handed a different long random value by hand. Is that generation?
    No, but it is better than one shared value. There are now two static credentials with fewer holders each, so one escaping reaches less. It is still not generation: nothing can produce a third on request and nothing can destroy either one without a person doing it, which is exactly the capability the word names.

A locksmith cutting a very intricate key does not change the fact that forty people carry a copy of it. A front desk that cuts a fresh card per guest can cancel one guest's card without touching the door or anyone else's.

saying these in an interview costs you the question

  • A long random string is by definition a generated credential
  • Static means the value is weak, short or human-chosen
  • Storing the random value in a store makes it generated
  • If no person typed it, it counts as generated
  • Entropy decides whether one holder can be cut off alone