skip to content

Why does '4,000 credentials captured' price neither a password lot nor a live session?

level: seniorimportance: nice to knowfreq 34%

answer

  1. a count is a production statistic
  2. unverified by construction
  3. two goods, two clocks
  4. one can be warehoused, one cannot
  5. price follows whose accounts they are

basics

~20 s

A count is not an inventory. It mixes two goods with different clocks, unverified passwords that die at the next reset and live sessions that die when the session ends, and it never says whose accounts these are, which is what a buyer is actually paying for.

solid answer

~50 s

The number is a production statistic, and price is set by three things it omits. First, liveness: harvested passwords are unverified by construction, so a lot is priced per thousand against an assumed survival rate, not a known one. Second, the clock: a password decays slowly and can be warehoused, split and resold, while a session expires on the service's own schedule and has to be handed over and used almost at once, so it sells once, per access, at a far higher unit price. Third, identity: four thousand consumer mailboxes are a breadth commodity, while forty accounts inside one named organisation are a depth product sold to a different buyer entirely. An access broker who never intrudes further makes money precisely by knowing which of those two markets a given batch belongs to, and a raw count answers none of it.

go deeper

for a junior

Recall the two products and their clocks: a password dies at the next reset, a session dies when the service ends it. A raw count does not say which you are looking at.

for a middle

Explain why a harvested lot is unverified by construction and therefore priced on an assumed survival rate, while a relayed session is verified by construction because the service issued it.

for a senior

Reason like the seller: liveness, clock, exclusivity, freshness and whose accounts these are. Show why the same operator serves a breadth buyer and a depth buyer from one lure.

for a principal

Own the argument that headline capture numbers drive bad prioritisation on both sides of the market, and that the useful question is always which product, whose accounts, and how old.

## The claim being tested A single lure can be converted two ways, and a capture count treats the results as one thing. The interviewer is checking whether you can price inventory the way the operator does, because that is what predicts what happens next. ## Good one: an unverified password lot Harvested passwords are strings nobody has checked. Every lot contains typos, stale passwords, garbage from suspicious victims and dead accounts, in proportions the seller does not know either. The seller does not usually find out, because checking is a separate activity with its own cost, so verification is pushed onto the buyer. That shapes the price directly. Bulk lots trade per thousand at a level that already assumes most entries are worthless; the buyer is paying for a statistical expectation and monetising the surviving fraction. The good decays continuously as victims rotate passwords, and it decays faster once anything prompts a broad reset. But it decays slowly enough to be warehoused: a file can be held for weeks, split, and sold more than once, which caps the unit price because exclusivity is not part of the offer. ## Good two: a live session The session captured by a relay is the opposite kind of good in every respect that matters commercially. It is verified by construction, because the genuine service issued it only after a real authentication succeeded, so there is no live-rate discount at all. It cannot be warehoused: it expires on the service's clock regardless of what anyone does with it, so it must be delivered and used inside its own lifetime. And it cannot honestly be resold twice, because two buyers cannot both be first. So it prices as one access, not as one unit, and the number attached to it is orders of magnitude away from a per-thousand rate for passwords. Comparing the two on the same scale is the error the question is aimed at. ## What the count also hides: whose accounts Price follows identity more than volume. Four thousand consumer mailboxes are breadth: the buyer wants many doors and does not care which. Forty accounts at one named manufacturer are depth: the buyer wants that organisation, and may pay more for the smaller lot precisely because it is the smaller lot. A count with no tenant attached cannot be placed in either market. This is why the same operator sells to both. The lure is the expensive part to run once; the conversions come out of it as two product lines, and an access broker who never intrudes further makes their margin by sorting the output correctly rather than by using any of it. ## Freshness as a priced attribute Because both goods decay, time since capture is quoted the way a perishable good's date is quoted. A batch offered the same day is a different product from the same batch three weeks later, and the two clocks run at wildly different speeds: three weeks costs a password lot some fraction of its live rate, and costs a session everything. ## How to answer without overclaiming The strong version names the axes and refuses to give one number: liveness, clock, identity, exclusivity and freshness. Then it says what the count actually is, which is a measure of how well the lure performed, not a measure of what came out of it. The two are only loosely related, and an operator who confuses them prices their own inventory badly. ## The trap in the other direction Do not swing to saying the count is meaningless. It bounds the upper end, it tells you the lure ran at scale rather than against a handful of chosen people, and a batch that large implies an untargeted delivery rather than a hand-built pretext for one person. That is a real inference about how the operation was run. It is simply not a price.

  • Which of the two products can be warehoused, and which cannot?
    Password lots can. They sit in a file, decay slowly with each reset, and can be held, split and sold more than once, which is exactly why the per-unit price is low. Live sessions cannot: the good expires on the service's own clock and has to be handed over and used almost immediately, so it is sold once, as one access, at a far higher price.
  • Why is a lot of 40 credentials sometimes worth more than a lot of 4,000?
    Because price follows whose accounts they are. Forty accounts inside one named organisation are a targeted access product with a specific buyer; four thousand consumer mailboxes are a bulk commodity priced on an assumed live rate. Only one of those buyers is paying for a particular victim, and that is the one who pays more per entry.
  • What is the buyer of an unverified lot actually paying for?
    A statistical expectation. The price per thousand already assumes most entries are dead, mistyped, stale or reset, and the buyer carries the cost of finding out which are not. The seller monetises volume and the buyer monetises the surviving fraction, which is why verification cost, not capture cost, sets the market rate.
  • Is the capture count useless, then?
    No, it is just not a price. It bounds the maximum, and it says something real about how the operation was run: four thousand submissions implies untargeted delivery at scale rather than a hand-built pretext aimed at a few named people. That is an inference about method, not about what the output is worth.

Pricing this by the capture count is like pricing a delivery by counting crates, without saying whether they hold apples or fresh milk, or how many days ago they were packed.

saying these in an interview costs you the question

  • Treats the capture count as the severity of the event
  • Assumes captured credentials have all been verified as working
  • Prices stolen sessions and harvested passwords on the same scale
  • Ignores which organisation the accounts belong to
  • Thinks a live session can be stockpiled and sold months later
  • Assumes a bigger lot is always the more valuable one

context