What verification survives a caller who has the right voice, the right number and weeks of rapport?
answer
- who produced each signal?
- rapport was bought, not earned
- shared knowledge is researchable
- a path the caller did not choose
- urgency prices out the check
basics
~20 sOnly a check that consumes a fact the caller did not supply and cannot influence, reached over a path they did not choose. Shared knowledge fails - weeks of friendly contact is how that history was manufactured.
solid answer
~50 sEvery signal in that list came from the caller, so none of them can settle the question. The invariant is that the verifying fact must be one the caller neither supplied nor could influence, obtained over a path the caller did not choose. That rules out the voice, the presented number, the thread context, and the one seniors reach for first: a shared-knowledge challenge. A patient operator spends the front of the operation acquiring exactly that context - three weeks of ordinary, useful contact is a cheap way to buy the answers to "something only they would know". Rapport is not evidence; it is the product that was purchased. What survives is reaching the claimed identity at an address you already held, or confirmation from a party the caller has no relationship with. The second requirement is time, because the pretext supplies urgency precisely to make the check look unaffordable.
go deeper
Recall that anything the caller tells you - number, voice, names, shared history - came from the caller, so none of it can confirm who they are.
Explain why a knowledge challenge fails against a patient operator: the research and the weeks of friendly contact are how the answers were collected in the first place.
Give the check as an invariant rather than a script - a fact the caller did not supply, over a path they did not choose - and state that it must be allowed to take time and cannot be improvised mid-call.
Own the tradeoff that makes it real: an identity path agreed with each supplier before it is needed, scoped to actions worth delaying, with the false-rejection cost named rather than wished away.
## Sort the signals by who produced them The scenario is deliberately loaded: a named engineer on an outsourced overnight desk for a Linux server fleet, a number that presents as the supplier's, a voice that matches a person whose recorded talks are public, and three weeks of pleasant, genuinely useful correspondence before the first real ask. It feels overwhelming, and it becomes tractable the moment you sort the evidence by **who produced it**. - The voice: produced by the caller. - The presented number: asserted by the originating side of the call. - The thread and its history: initiated and shaped by the caller. - The shared details, names and running jokes: accumulated by the caller during those three weeks. The list is not four pieces of evidence. It is one piece of evidence, repeated four times, and its source is the party whose identity is in question. ## The invariant A verification survives only if it consumes **a fact the caller neither supplied nor can influence, obtained over a path the caller did not choose.** Both halves matter. A fact the caller did not supply but which they can steer you toward - "my colleague can confirm, here is her number" - fails the second half. A path you chose but which asks the caller to produce something - reading back a reference the caller gave you - fails the first. In practice the shapes that satisfy the invariant are narrow: reaching the claimed identity at an address of record you already hold, or confirmation from a party with whom the caller has no relationship and whose contact details predate the call. Both are unglamorous, and both are only available if someone arranged them before the night in question. ## Why the knowledge challenge is the interesting wrong answer Asking "something only the real person would know" is the answer a competent senior engineer gives, and it is wrong for a reason worth stating carefully. It feels like an authenticator because the answer is unguessable *by a stranger*. But by the time the ask lands, the operator is not a stranger. Consider the economics of an adversary with time and no revenue target: no return has to be produced this quarter, so spending three weeks being a helpful, unremarkable contact is affordable. Every one of those interactions is a collection opportunity. Project names, the fact that a migration slipped, who is on holiday, what the desk calls the change process, which engineer sighs about the ticketing system - this is precisely the raw material a knowledge challenge draws on. **The rapport was not a side effect of the operation; it was the purchase.** There is a second failure. Knowledge challenges are researchable from outside as well as from inside. Organisations publish an enormous amount of exactly the kind of internal-flavoured detail that feels private: org charts in conference talks, project names in job adverts, supplier relationships in press releases, tooling in engineering blog posts. A challenge built from that material tests reading comprehension. ## Time is part of the control The pretext supplies urgency for one purpose: to make the verification look more expensive than the request. A control that yields under pressure is not a control that sometimes fails; it is a control that fails against every competent operator and holds only against clumsy ones. So "the check must be permitted to take time" is not an operational nicety, it is part of the specification. That in turn means the person receiving the call cannot be the one deciding whether the check is affordable. ## The cost you must be honest about This check will reject real people. A genuine overnight engineer, on a rotating rota, calling about something legitimate, will fail an identity check that depends on an address of record you hold - because you do not hold one for them. That is not an argument against the check; it is an argument for agreeing the path with the supplier before it is needed, and for scoping the gate to actions where the delay is worth it. Pretending the false-rejection cost is zero is how a rule gets quietly abandoned. ## Answering it well Sort the signals by producer. State the invariant in one sentence. Explicitly reject the shared-knowledge challenge and explain the economics that defeat it - patience buys shared history. Name the narrow set of checks that satisfy the invariant. Then add the two conditions that make it survive contact with reality: it must be allowed to take time, and it must have been arranged in advance, because nothing satisfying the invariant can be improvised during the call it is meant to test.
- Why is a shared-secret challenge attractive and still wrong?It feels like an authenticator because a stranger could not answer. The operator is not a stranger by then: the reason to spend weeks as a helpful contact is to accumulate the names, history and internal vocabulary such challenges draw on, and much of the rest is published by the company itself. Any question answerable from research or prior conversation is one the operation was designed to pass.
- Does a legitimate supplier engineer ever fail this check, and what does that cost?Often, at first. A real overnight engineer on a rotating rota fails a check that depends on an address of record you hold, because you hold none for them. That is the argument for agreeing the path with the supplier in advance rather than inventing one at 03:00, and for scoping the gate to actions where a delay is worth paying. The cost is delayed work, and it is the price of the property that makes the check mean anything.
- The caller offers a manager who will vouch for them. Why does that not help?Because the caller chose the path. A reference supplied during the call is another caller-produced signal, whether it is a number to ring, an address to write to or a name to look for. The invariant is not that a second person confirms; it is that the confirming route was one you already held before the call arrived.
saying these in an interview costs you the question
- Proposes a shared-secret or 'only they would know' challenge
- Treats long friendly history as evidence of identity
- Accepts a callback number the caller reads out
- Lets the caller's urgency shorten or skip the check
- Confuses knowing about the company with belonging to it