What makes a communications channel genuinely out-of-band during a suspected intrusion?
answer
- think about shared dependencies
- brand of the app is not the test
- who authenticates the participants?
- identity, transport, devices, membership list
- same SSO tenant is still one room
basics
~20 sOut-of-band means the channel shares no dependency with the systems under investigation: different transport, different identity provider, different devices, and a member list not drawn from the compromised directory. A second app behind the same sign-on is still in-band.
solid answer
~50 sThe test is dependency, not brand. If the intruder holds a valid session or an administrative role in the estate, anything that authenticates through that estate's identity provider, runs on its managed devices, or draws its membership from its directory is readable by them. So switching from one corporate chat app to another federated to the same SSO changes nothing. A genuinely out-of-band channel authenticates its participants some other way (a phone call to a number you already knew, a secure messenger on personal devices, a bridge in a separate tenant), runs where the adversary has no admin rights, and is joined by people you invited individually rather than by a group synced from the compromised directory. Remember also that resetting a password does not by itself invalidate an already-issued session token or OAuth grant, so "we reset their account" is not proof the room is now private.
go deeper
Be ready to define out-of-band in one sentence and give the dependency test: identity, transport, devices, membership. Know that a second app behind the same SSO is not a move.
Explain why an adversary who is a channel member defeats encryption entirely, and why revoking a password leaves sessions and tokens alive until they are explicitly revoked.
Show that you weigh the cost: a smaller room loses context, personal devices create records and legal-hold problems, and you need explicit criteria for returning on-band.
Own the pre-incident version of this: whether the organisation has an independent tenant, an offline contact roster and a rehearsed bridge before the day it needs one, and who pays for it.
## The idea During an intrusion, the response itself is sensitive information. Your working hypothesis, the hosts you are about to isolate, the accounts you are about to disable, the hour you plan to cut access, the fact that you have noticed at all - every one of those is intelligence that helps an adversary who can read it. If that adversary holds a valid session in your collaboration suite, or administrative rights over the mail platform or the identity provider, then discussing the incident in the estate's own tools is briefing them. **Out-of-band** is the term for moving that discussion somewhere the adversary's access does not reach. The word is borrowed from signalling: the control conversation travels on a path separate from the data path being controlled. ## The test is a dependency test, not a product test The most common junior mistake is to treat "a different app" as out-of-band. Ask instead which of the compromised estate's components the candidate channel depends on: - **Identity.** Does it log in through the same single sign-on or directory? If yes, whoever holds admin in that identity provider can mint a session, add themselves, or read the tenant's audit and export APIs. Two different chat products federated to one compromised identity provider are one channel. - **Transport and hosting.** Is it in the same cloud tenant, behind the same VPN, or served through the same proxy the adversary can see or control? - **Devices.** If the endpoints in scope may carry an implant with screen or keystroke capture, a "secure" app on those same laptops is still exposed. This is why responders sometimes fall back to personal phones or a small number of known-clean machines. - **The membership list.** If you invite people using a group synced from the compromised directory, or by looking up numbers in the compromised address book, you may invite the adversary or reach the wrong person. The roster has to come from somewhere they do not control. A channel that fails any one of those four is in-band no matter what its marketing says. ## Why an adversary in the room is different from an eavesdropper on the wire Encryption is not the property you need here. The threat model is not somebody sniffing traffic; it is somebody holding a legitimate credential and sitting inside the conversation as a member. End-to-end encryption does nothing against a participant. That is why "we use an encrypted chat tool" is not an answer, and why membership discipline matters as much as the technology. ## What people get wrong about eviction Removing the suspect account from the channel, or resetting its password, feels like it restores privacy. It usually does not, at least not immediately: - A password change does not automatically invalidate an already-issued session cookie, refresh token, OAuth grant or application token; those need explicit revocation. - Anything already posted in the channel has already been read or synced to a client; you cannot un-send it. - Kicking the account out is also a visible action, and telling an intruder that you have spotted them is a decision that belongs to the incident lead, not a reflex. So the correct posture is: assume everything written in the in-band channel up to now is in the adversary's hands, and move the sensitive part of the conversation somewhere new. ## The costs, which are real Out-of-band communication is slower and smaller. Fewer people are in the room, so decisions lose context and the people left outside fill the silence with rumour. Personal devices and personal messengers create records problems: the incident record still has to be preserved and may later be read by lawyers, auditors or a regulator, and a conversation held on someone's personal phone is awkward to produce. Where possible the channel is company-run but *independent* - a separate tenant with its own identity, or a conference bridge from a different provider - rather than genuinely personal. You also need an exit. The out-of-band channel is a temporary measure for the period in which you cannot trust the estate; once the adversary's access is removed and you have some assurance it stays removed, the conversation comes home and the record is consolidated into the case file. ## What a good short answer sounds like "Out-of-band means it does not depend on anything I am investigating - not the same identity provider, not the same tenant, not the same devices, not the same address book. If our SSO is compromised, moving from one corporate chat tool to another one behind that SSO is not a move at all."
- The suspect account has been disabled and its password reset. Is the original channel safe to use again?Not on that basis alone. A password reset does not invalidate sessions, refresh tokens, OAuth grants or application tokens that were already issued, and it says nothing about other footholds such as a second account, a mail forwarding rule or an admin role. Treat the channel as safe only once you can show those sessions were revoked and no other identity in the tenant is suspect - and even then, assume everything previously posted is known.
- When do you move the conversation back on-band?When the reason for leaving is gone: the adversary's access has been removed, you have some monitoring that would show re-entry, and no remaining hypothesis depends on the estate being untrusted. Moving back is a deliberate decision, not a drift, and the out-of-band record has to be gathered into the case file rather than left on people's phones.
- Does using an end-to-end encrypted messenger make a channel out-of-band?No. Encryption protects against someone intercepting traffic; it does nothing against someone who is a member of the conversation or who controls the device it is displayed on. If the adversary can add themselves through a compromised identity provider, or is reading the screen of a compromised laptop, the encryption is irrelevant. Out-of-band is about dependency and membership, not cryptography.
Calling the police from the burglar's own landline. It is a different handset, but it is still their wire.
saying these in an interview costs you the question
- Says moving from one corporate chat app to another is out-of-band
- Treats end-to-end encryption as sufficient against a member of the channel
- Assumes a password reset immediately evicts a live session
- Invites participants from a group synced out of the compromised directory
- Believes deleting the messages removes what was already read