skip to content

A quarterly cadence is defended as capping an undetected leak at ninety days — what does that arithmetic assume?

level: seniorimportance: nice to knowfreq 28%

answer

  1. a ceiling, with conditions attached
  2. worst case, not expected case
  3. closed escape path is assumed
  4. harm as a rate, not an event
  5. only pays where detection is slower

basics

~20 s

Four things: the access that produced the copy is closed, the old value genuinely stops authenticating, harm accrues over the window rather than in one act, and detection is slower than the interval. Break any one and the cap is fiction.

solid answer

~50 s

The figure is an upper bound that rests on four conditions. First, the intruder cannot take a fresh copy — otherwise each replacement is simply handed over and the window is unbounded. Second, the old value actually stops being accepted; installing a new one beside it bounds nothing. Third, the harm is proportional to how long the copy works: where the access allows a single bulk action, ninety days and nine minutes are the same number. Fourth, the cadence is only doing work in the region where detection is slower than the interval — if misuse would be noticed in hours, the cap is bounding a tail you already handle another way. It is also the worst case, not the typical one; under evenly spread theft timing the average window is near half the interval.

code

pseudocode · 20 lines
pseudocode
// One leaked shared credential, fixed 90-day replacement cadence
leakedOnDay            = 1     // unknown to the defender
newValueInstalledOnDay = 90
oldValueStopsWorking   = 90    // the withdrawal, not the install

usefulWindowDays = oldValueStopsWorking - leakedOnDay   // 89
harmAvoidedDays  = usefulWindowDays

// Assumption 1: the access that produced the first copy is closed
if intruderStillHoldsTheEscapePath:
    // day 90 delivers the replacement value to them as well
    usefulWindowDays = UNBOUNDED

// Assumption 2: the old value is stopped, not merely superseded
if oldValueStillAuthenticates:
    usefulWindowDays = UNBOUNDED

// Assumption 3: harm accrues over the window, not in one act
if harmCompletedOnDay(leakedOnDay):
    harmAvoidedDays = 0    // the cadence changed nothing in this incident

go deeper

for a junior

Recall that a replacement schedule gives a maximum exposure time, not a guarantee that a leak was harmless.

for a middle

Explain the endpoints of the window — theft to withdrawal — and why the figure is a worst case whose typical value is roughly half the interval.

for a senior

Show that you check the conditions before quoting the number: escape path closed, old value actually refused, and harm that accrues over days rather than completing in one action.

for a principal

Turn it into a spending decision — exposure reduction per production change, and the recognition that below some interval the right move is to change how the value is issued rather than how often it is replaced.

## Where the number comes from The claim is an upper bound on how long a copy taken **without anyone noticing** keeps authenticating. Its two endpoints are the moment of theft and the moment the old value stops working. In a ninety-day cycle, a copy taken on day 1 and withdrawn on day 90 gives 89 days. Two distributional points come before the assumptions: - It is the **worst case**. If theft is equally likely on any day of the interval, the expected window is near half of it, so halving the interval roughly halves the typical exposure and exactly halves the guaranteed maximum. - It is **conditional on non-detection** throughout. The cadence is not a detection control and never competes with one; it is what bounds the case where detection never fires. ## Assumption 1 — the escape path is closed The arithmetic assumes the intruder cannot repeat the theft. If the place the copy came from is still reachable — a foothold on a host that reads the value, an output where it is rendered, an inbox it is mailed to — then the replacement is delivered along with everything else and the window never closes. In that state a **shorter** cadence is worse than useless: it increases the frequency of handovers and produces an audit story that says the credential is rotated often. ## Assumption 2 — the old value is stopped, not merely superseded Replacement and withdrawal are separate actions. Generating a new value and moving your consumers to it changes nothing for someone presenting the old one; the accepting system has to be told to refuse it. Removing the value from wherever it was held is not the same thing either — a record deleted in a store does not make a downstream account reject the password it still has configured. ## Assumption 3 — harm accrues over time This is the assumption the arithmetic hides most effectively, because the units look like time on both sides. The window is measured in days; the harm is not necessarily. | Shape of the access | What shortening the cadence buys | |---|---| | One bulk read or export, finished in minutes | Essentially nothing — the harm completed on day one | | A foothold used to mint separate, longer-lived access | Nothing after the first few minutes; the new access outlives the cadence | | Steady low-volume use whose payoff accumulates | Real reduction, roughly proportional to the interval | | Resale of a working copy to another party | Real reduction, since the copy's worth is its remaining life | Where the top two rows describe your access, the cadence is buying very little and the change risk is being paid for nothing. That is the calculation a blanket cadence never performs. ## Assumption 4 — detection is slower than the interval If a credential's misuse would be recognised within hours — an unexpected caller, an unusual hour, a volume nobody needs — then the ninety-day cap is bounding only the cases detection misses entirely. That does not make it worthless, because the cases detection misses are precisely the ones that hurt, but it changes the size of the prize and it should change how much change risk you are prepared to accept for it. ## What the arithmetic is still good for All four conditions can be checked, which makes the number better than the platitude it replaces: - It converts "we rotate regularly" into a defensible statement about a worst case, with named preconditions. - It makes the change-risk trade explicit: a specific exposure reduction against a specific number of production changes per year. - It exposes the values where the ceiling is the wrong control entirely, because they are already bounded more tightly by how they are issued. The failure mode to avoid is quoting the ceiling as a fact about an incident. After a real leak, the honest statement is what the copy could have done in the window and what it did, not that the cadence limited the damage to ninety days.

  • If halving the interval halves the guaranteed window, why not halve it again?
    Because the benefit falls linearly while the cost does not. Each run is a production change with its own failure probability and coordination cost, and below some interval the expected loss from the changes themselves exceeds the exposure being removed. Past that point the honest move is to change how the value is issued rather than how often it is replaced.
  • What does the ceiling say about an incident that has already been detected?
    Nothing. The bound is defined over the case where nobody noticed; once detection has fired, the real window runs from the theft to whenever the value is actually stopped, which is a matter of hours or days and has nothing to do with the schedule. Quoting the cadence in an incident write-up is a category error.

saying these in an interview costs you the question

  • A cadence caps exposure regardless of how the leak happened
  • The ninety days is the typical exposure, not the worst case
  • Halving the interval halves the harm from a leak
  • A rotation schedule is a substitute for noticing misuse
  • The cap holds even while the old value is still accepted