One exposed key signs stored records and another encrypts them — why do the two exposures demand different remedies?
answer
- opposite directions in time
- disclosure against ongoing capability
- withdrawal helps one of them
- forgeries can predate the discovery
- mathematics unchanged, trust gone
basics
~20 sAn exposed encryption key costs past confidentiality: whatever it encrypted and someone copied is readable forever. An exposed signing key costs future trust: its holder can mint records that verify until every verifier stops accepting it, and recent signatures fall into doubt.
solid answer
~50 sThe two point in opposite directions in time. An encryption key exposure is a **disclosure** — the damage is already done to every copy that left, nothing you do reaches it, and the work is scoping what was covered plus re-encrypting the copies you still hold. A signing key exposure is an **ongoing capability** — the holder can produce records that verify, starting from the moment they got the key and continuing until every verifier stops accepting it. So the urgent action is getting that key out of the accepted set everywhere, which actually does stop the attack, in a way that no action stops an encryption disclosure. There is also a backward tail: any signature made since the earliest possible copy is unproven, because a valid signature no longer distinguishes your writes from theirs.
go deeper
Recall the difference in purpose: one key keeps data secret, the other proves a record came from you. Losing each one costs a different property, so the response differs.
Explain the time directions — an encryption exposure is a disclosure that already completed, a signing exposure is an ability to forge that continues until verifiers stop accepting the key.
Show that you act on the signing case first because it is still running, that you measure discovery-to-withdrawal across every verifier, and that you mark the signatures in the doubtful window as unproven rather than valid.
Own the question of what the organisation can still prove. Decide in advance whether an independent record of signing times exists, because that decision, made long before an incident, is what bounds the doubt when one happens.
## Two keys, two directions in time The same event — key material in a place it should not be — produces two very different incidents depending on what the key was for. - An **encryption key** protects confidentiality. Exposure is about the **past**: everything it encrypted that anyone copied is now readable, permanently, and no later action reaches it. - A **signing key** produces something verifiers accept as yours. Exposure is about the **future**: the holder can produce new records that verify, and will keep being able to until every verifier stops accepting that key. The practical consequence is that the two incidents have different clocks. The encryption incident has already happened and the response is assessment and cleanup. The signing incident is still happening while you talk about it, and the response is an operation against every verifier. ## An exposed encryption key: the past is fixed What you can still do is bounded and unglamorous: - **Scope it**: which records the key covered and over what window. - **Re-encrypt** the copies you still control, including backups, replicas and exports. - **Retire** the key so your own systems stop reading with leaked material. What you cannot do is take back a copy. The confidentiality of anything already outside your estate is gone, and a response plan that does not say so out loud is misleading whoever reads it. ## An exposed signing key: two problems, not one **Forward.** Until verifiers stop accepting the key, the holder can produce records that pass. Fixing this is a distribution problem: every place that checks signatures has to be told, and the exposure lasts as long as the slowest verifier takes to learn. That is why the discovery-to-withdrawal interval is the number to manage. **Backward.** Even after withdrawal, everything signed between the earliest moment the key could have been copied and the moment you noticed is **unproven**. Those signatures still verify — the mathematics did not change — but verifying no longer tells you who produced them. That is the whole point of the exposure. | | Exposed encryption key | Exposed signing key | |---|---|---| | Property lost | Confidentiality of what it covered | Authenticity of what it vouches for | | Direction | Backwards, and final | Forwards, plus a backward window of doubt | | Does withdrawal stop the holder? | No — they never needed your systems | Yes, at each verifier that learns of it | | Main work | Scope, re-encrypt your copies, retire | Withdraw everywhere, re-sign, re-verify the doubtful window | | What you cannot undo | The copies already taken | Acceptance that already happened | ## What shrinks the window of doubt The doubt is not always total. It shrinks when something **independent of the exposed key** recorded that a signature already existed at a given time — a countersignature from separate key material, or an append-only record whose own integrity does not rest on the exposed key. Where such a thing exists, signatures it covers can still be trusted, and only the remainder is in question. Where it does not exist, the honest boundary is the earliest moment the key could have been copied — often the creation of the file it was exported into, which may be much older than the discovery. Assume the wider window unless something narrows it. ## Where candidates swap the two - Saying rotation "invalidates" forgeries already produced. It does not: the forged record keeps verifying anywhere the old key is still accepted, and withdrawal is what changes that. - Saying re-encryption is the remedy for a signing key. Re-encryption changes confidentiality; the signing key never opened anything. - Assuming withdrawal is instantaneous. It propagates at the speed of the verifiers, and any verifier that never learns keeps accepting forgeries indefinitely. - Believing that re-signing content under a new key clears the doubt. It vouches for the content *now*; it says nothing about whether the content was altered before you re-signed it. - Running one playbook for both. The encryption incident is a disclosure assessment; the signing incident is a live capability to shut down. ## The sentence to lead with "Which kind of key is it?" — because the answer decides whether you are containing an ongoing ability to forge, or measuring a disclosure that already completed. Getting that wrong costs hours in the direction where hours matter most.
- What lets you keep trusting signatures made before the exposure was discovered?Something independent of that key which recorded the signature already existed — a countersignature from separate material, or an append-only record whose integrity does not rest on the exposed key. Without one, the honest boundary is the earliest moment the key could have been copied, and everything after it is unproven rather than trusted.
- Does re-signing all the records under a new key clear the doubt?Only forwards. Re-signing says you vouch for the content now; it says nothing about whether the content was altered during the doubtful window. If the content itself could have been forged, you have to check it against an independent source of record — the signature cannot answer a question about itself.
A stolen reading glass and a stolen rubber stamp: the first lets the thief read what you wrote, the second lets them write things in your name.
saying these in an interview costs you the question
- Says replacing a signing key invalidates forgeries already accepted
- Treats an exposed encryption key as fixed by re-encryption
- Assumes verifiers stop accepting a key the moment you withdraw it
- Runs the same playbook for both kinds of key
- Forgets forged signatures can predate the discovery