Your archive keeps secret store backups for years - how long should the material that opens them live, and what does each answer cost?
answer
- two clocks, not one
- retained ciphertext is deferred exposure
- destroying key material unreadable cheaply
- recovery guarantee becomes custody guarantee
- least-controlled copy decides the claim
basics
~20 sKeeping the opening material as long as the ciphertext keeps every old backup recoverable, and a disclosure waiting on that material. Retiring it sooner makes the archive noise, cheaply and irreversibly, and trades recoverability for custody.
solid answer
~50 sThis is a trade with no default answer, and the honest framing is that retaining ciphertext is retaining the secrets inside it, deferred. At one end you keep the opening material as long as any copy exists: every archived backup stays openable, which is what someone wanted, and every one becomes a live disclosure the day that material is copied somewhere weaker. At the other end you retire it on a much shorter clock: the older ciphertext becomes noise, by far the cheapest way to render a large archive unreadable, but you have swapped a recoverability guarantee for a custody one and get no appeal if you were wrong about which copies you needed. Most estates land on a short window where opening material is available, a longer tail where it is not, and an explicit decision about which copies are kept for recovery rather than kept because nobody deleted them.
go deeper
Recall that an archived copy is only inert while the material that opens it is out of reach, so keeping copies for years means keeping that question open for years.
Explain the two clocks separately: how long the ciphertext is retained, and how long the material that opens it lives. They are set by different people for different reasons.
Show that retiring the opening material is a deliberate control with a cost, and check the conditions that make it real - every copy gone, evidenced at the time, tied to the copies it opens.
Own the trade in the open: name the recoverability window, the tail where copies are deliberately unrecoverable, and the category of copies kept simply because nobody deleted them.
## What the question is really about An obligation somebody else owns requires the archive to exist for years. The store's backups are ciphertext, which feels like it settles the risk. It does not, because the ciphertext's value is set entirely by the availability of the material that opens it - so the retention decision you actually control is the **lifetime of that material**, and it is a decision a lead owns rather than a setting an operator picks. The framing to hold onto: **retaining ciphertext is retaining the secrets inside it, deferred.** You are not choosing whether to keep them. You are choosing the condition under which they come back. ## The two ends of the trade **Keep the opening material as long as any copy exists.** - Every archived copy remains openable, which is the property whoever asked for multi-year retention believed they were buying. - Every archived copy remains a live disclosure, conditional on that material leaking, being copied to a weaker location, or being retained by someone who leaves. - Custody must hold for the whole retention period, across re-homing, re-organisations and technology changes. That is a long time to guarantee anything. **Let the opening material retire on a shorter clock.** - The older ciphertext becomes noise. Destroying a small amount of key material is the cheapest way there is to make a very large archive unreadable, and unlike deleting files it works on copies you do not physically control. - The guarantee changes kind. You no longer promise 'we can restore this'; you promise 'we destroyed that material', which is a claim about process, not about bytes. - It is irreversible, and it fails badly if you were wrong about which copies were still needed. There is no partial recovery and no appeal. ## Three conditions that decide whether the shorter clock is real 1. **Every copy of the material must be gone.** An escrowed copy, a second-site replica, a printed share in a safe, or one in an older archive of the archive defeats the whole scheme. The claim is only as good as the least-controlled copy. 2. **The claim has to be evidenced.** From the outside, 'we destroyed it' is unfalsifiable; if an obligation depends on it, you need a record made at the time, not an assertion afterwards. 3. **The clock must be tied to something real.** Retiring material on a schedule nobody mapped to the copies it opens produces a surprise: an archive you believed recoverable and cannot open, discovered at the worst moment. ## The third variable people forget How often the values inside are replaced changes the arithmetic more than either clock. Assume a two-year archive. If every value in the store is replaced on a cycle measured in weeks, a backup older than a few months exposes almost nothing live even if fully opened, and the lifetime of the opening material barely matters. If a large share of the values have not changed in years, every archived copy is close to a full disclosure, and the lifetime of that material is the only thing standing between you and it. **Ask what is inside before arguing about the clocks** - and note that the cheapest fix is often to make the contents replace faster, not to re-engineer the archive. ## What a lead should actually set - A stated **recoverability window** during which opening material is deliberately available, ideally much shorter than the retention period, chosen from what recovery genuinely needs rather than from what the archive happens to hold. - A **tail** where copies persist because an obligation requires them, with the opening material retired - and an explicit, recorded acceptance that those copies are not recoverable. - A distinction, written down, between copies **kept for recovery** and copies **kept because nobody deleted them**. The second category is where this whole risk accumulates, quietly, and it never appears in a design document. - A review that catches the drift: material retained 'just in case' past its window, and copies that outlived the reason they were made. The answer an interviewer is listening for is not a number of years. It is whether the candidate sees that the two clocks are separate, that one of them can be used deliberately as a control, and that using it exchanges one guarantee for another rather than removing risk for free.
- What single fact would most change your recommendation here?How often the values inside the backups are replaced. If everything the store holds turns over in weeks, an old copy exposes almost nothing live and the argument about clocks is mostly theoretical. If large numbers of values have sat unchanged for years, every archived copy is close to a full disclosure and the lifetime of the opening material is the only control in play.
- Somebody proposes keeping the opening material forever so nothing is ever unrecoverable. What is the cost?You have committed to holding that material securely for the entire retention period, across re-homing, staff turnover and technology changes, and you have accepted that every copy in the archive becomes a live disclosure the day custody fails once. The recoverability is real; it is simply not free, and the bill arrives all at once.
- How would you evidence that the shorter clock actually happened?A record made at the time of destruction, naming what was destroyed, which copies it opened and who witnessed it, plus an inventory showing no other copy of that material remains. After the fact, nothing distinguishes destroyed material from material somebody kept, which is why the evidence has to be produced as part of the act.
Keeping the archive but destroying what opens it is like keeping a filing cabinet and dropping its only key into the sea - wonderfully cheap, entirely irreversible, and worthless if a spare key exists.
saying these in an interview costs you the question
- Says archived backups are safe because they are encrypted
- Treats destroying the opening material as free with no recovery cost
- Forgets escrowed or off-site copies of that material
- Assumes changing the protecting key makes old copies unreadable
- Argues the clocks without asking how often the contents are replaced
- Offers a number of years with no reasoning behind it