skip to content

Your store now mints accounts in a reporting warehouse — why is the store's own identity there more dangerous than any credential it hands out?

level: seniorimportance: must knowfreq 52%

answer

  1. look at the minter, not the minted
  2. it can create anything it may grant
  3. a standing administrator in someone's system
  4. its ceiling is what it holds
  5. one identity per downstream system

basics

~20 s

Because it can bring new principals into existence with any rights it is allowed to grant, for as long as it exists. A minted account is one narrow slice; the identity that mints is the power to produce slices at will.

solid answer

~40 s

Everything the design gives you rests on one standing identity the store holds in the warehouse, and on most systems creating principals and attaching rights is an administrative capability. Compromise a minted account and an attacker holds one consumer's narrow rights; compromise the store's identity there and they can mint whatever that identity may grant, repeatedly, under names that look like ordinary issuance. So it is scoped as tightly as the system allows, held separately per downstream system, and — where the system enforces that a grantor may hand out only rights it holds — deliberately kept weak, because that makes it a **ceiling** on every account it will ever create.

go deeper

for a junior

Recall the asymmetry: a minted account is one consumer's narrow access, while the identity that creates accounts can produce more of them.

for a middle

Explain why create-and-grant is an administrative capability on most systems, and what a grantor limited to rights it holds gives you as a ceiling.

for a senior

Demonstrate the operating side: a separate minting identity per system, creation watched in that system's own records, alarms on rights outside the template, and a severing plan whose cost is known in advance.

for a principal

Own the trade explicitly — a long-lived shared value removed in exchange for a concentrated privileged identity — and say which downstream systems that trade is acceptable in and who signs for it.

## The identity that makes minting possible Per-consumer issuance is not magic performed by the store. It is the store, holding a standing identity in the downstream system, performing create-grant-remove on demand. That identity is the hinge of the whole design, and it has three uncomfortable properties at once: - It is **standing** — it exists between requests, not only during one, because the store must be able to serve the next consumer that starts. - It is **privileged** — on most systems, creating a principal and attaching rights to it is an administrative capability, not an ordinary one. - It is held by a **network service** that every consumer in the estate talks to, which is a far larger attack surface than a credential sitting inside one job. ## Why it outranks everything it hands out | If this is compromised | What the attacker holds | |---|---| | One minted consumer account | That consumer's rights, on that dataset | | The store's identity in the warehouse | The ability to create principals with any rights it may grant, repeatedly | The second row has properties the first does not. New principals it creates look exactly like ordinary issuance, because that is what ordinary issuance looks like. They can be created under names that match the estate's convention. And the capability persists: removing one abused account does not remove the ability to make another. There is a second, quieter asymmetry. A leaked minted account is bounded by the rights that account was given, which you chose. The minting identity is bounded by the rights the **system** will let it grant, which you may not have chosen at all — and if the only way to get create-and-grant in that system was an unrestricted administrator, then the design has quietly traded a shared read credential for a standing administrator. ## Bounding it 1. **One identity per downstream system.** A single credential that mints in five systems makes one compromise reach five. Separate them even when the store is the same. 2. **Grant the ceiling you want, where the system offers one.** Some systems enforce that a grantor may hand out only rights it holds itself. Where that is true, holding a deliberately weak minting identity makes it structurally impossible to mint anything stronger, whatever the store's rules say. Where the system does not enforce it, you have no ceiling and the narrowness of every account depends on the store's rules being right, so the rules deserve the review effort the ceiling would have saved. 3. **Do not give it rights to the data itself** where the system allows creating and granting without reading. This is not universally possible, but where it is, it means a compromise of the minting identity is a route to access rather than access itself — which costs the attacker a visible step. 4. **Watch principal creation in the downstream system's own records**, not only in the store's. The store's records say what it was asked to do; the system's records say what was actually created there, including anything created by some other route. 5. **Alarm on shape, not only on volume.** A created principal whose rights fall outside the template the store is supposed to produce is a strong signal, and a cheap one. ## The severing question An incident plan should state, before the incident, what happens when you cut the store's identity out of that system. Two things are true and are commonly confused: - Removing the minting identity **stops new issuance immediately**: no consumer can obtain an account there until it is restored, so anything that restarts during the window fails to start. - Removing the minting identity **does not withdraw accounts already minted**. Those are ordinary principals of the warehouse now; ending them is a separate action against the warehouse. Both sentences are worth saying in an interview, because the instinct under pressure is to assume that cutting off the minter also cuts off everything it made. It does not. And the cost of the first sentence — an estate that cannot obtain downstream credentials for the duration — is precisely why the decision belongs in a plan rather than in the moment. ## The judgment this demands The honest summary is that per-consumer issuance moves risk rather than deleting it. It removes a long-lived shared value that was sitting in several places, and in exchange it concentrates a privileged identity in one service. That is usually a good trade, because one privileged identity in a system you monitor is easier to defend than a shared value you cannot find every copy of. It is only a good trade if the concentration is acknowledged, scoped and watched — and if you could answer, today, which downstream systems your store can currently create principals in.

  • What does your incident plan owe you before you cut the store's identity out of a downstream system?
    The cost, stated in advance. Cutting it stops all new issuance there, so every consumer that restarts during the window fails to obtain an account — but it does not end accounts already minted, which are ordinary principals of that system and must be dealt with separately. A plan that assumes severing the minter also withdraws its output will act on a false sense of containment.
  • Why watch principal creation in the downstream system's own records when the store already records every request it served?
    Because they answer different questions. The store's records say what it was asked to do and believes it did; the system's records say what exists there, including principals created by a route the store knows nothing about — another operator, a leftover automation, or an attacker holding the minting identity. Agreement between the two is the signal; only one of them can be checked against reality.
  • A system only offers create-and-grant through an unrestricted administrator. What is the honest way to describe that trade?
    You are exchanging a shared read credential for a standing administrator in that system. Sometimes that is still right — the shared value had copies you cannot find and the administrator is one identity you can monitor and remove. But it must be stated that way to whoever owns the system, not presented as a pure reduction in risk.

A locksmith who can cut a key for any door in the building is a bigger problem than any single key they have cut, and stays one after every key is collected back in.

saying these in an interview costs you the question

  • Says the store only holds values, so it grants nothing
  • Takes an unrestricted administrator downstream because it is simpler
  • Believes minting removes the need for any privileged identity
  • Reuses one minting identity across every downstream system
  • Assumes cutting off the minter ends the accounts it made