A shared service credential is replaced every ninety days and an intruder copied it on day one unnoticed — what did that schedule cost the intruder?
answer
- a ceiling, not a cure
- bounds forward, never backward
- clock starts at the leak
- new value installed, old one still accepted
- withdrawal is what ends the copy
basics
~20 sAt most eighty-nine days of working access, and only because the old value was stopped from authenticating. A replacement cadence caps how long an unnoticed copy stays useful; it reverses nothing the intruder already did inside that window.
solid answer
~40 sThe cadence bought exactly one thing: a ceiling on how long the stolen copy went on authenticating. Taken on day 1 and withdrawn on day 90, that is 89 days of use — a worst case, not a typical one, since a copy taken on day 80 would have had ten. The ceiling only exists because the old value stopped being accepted; installing a new value beside a live old one bounds nothing. And it is forward-looking only: whatever the intruder read, exported, changed or created during those 89 days is untouched by the replacement, including any second credential they minted for themselves. If the access that produced the first copy is still open, day 90 simply delivers the replacement to them too.
go deeper
Recall the shape: replacing a credential limits how long a stolen copy keeps working, and it does not undo anything already done with it.
Explain the mechanics — the window runs from the theft to the moment the old value stops authenticating, so it is a worst case over the interval, and installing a new value is only half the change.
Show the operating judgment: name the two preconditions (old value actually stopped, escape path closed), and say when a shorter interval buys real exposure reduction and when it buys nothing because the harm completes in one act.
Frame it as a purchase — you are buying a bounded worst case with change risk and engineering time, and the price only makes sense where detection is slower than the interval and the access pays off over days rather than minutes.
## The one quantity the arithmetic gives you A fixed replacement cadence produces a single arithmetic result: an upper bound on how long a copy of a credential that somebody took **without your knowledge** goes on authenticating. In this scenario the copy was taken on day 1 and the old value stopped being accepted on day 90, so the intruder had **89 days** of working access. It is worth being precise about what kind of number that is. - It is a **ceiling**, not an expectation. A copy taken on day 80 gets a ten-day window from the same schedule. If a theft is equally likely on any day of the interval, the average window is near half of it — the cadence guarantees the worst case and only influences the average. - It bounds **future** use, measured forward from the moment the old value stops working. Nothing about it reaches backwards. - It exists **only because the old value stopped being accepted**. A new value written beside a live old one bounds nothing at all. - It says nothing about **detection**. A cadence is the control you are left with when detection failed; had the misuse been noticed on day 2, the schedule would never have entered the story. A cadence has a second product that is not arithmetic at all — a replacement path that has actually been exercised — and that is a separate subject from the ceiling this question is about. ## What the intruder keeps This is where most candidates overstate the benefit. The replacement ends the credential's usefulness going forward and does nothing else. | Bounded by the replacement | Untouched by the replacement | |---|---| | Further authentication with that stolen copy | Data read or exported while the copy still worked | | The copy's worth to anyone it was passed on to | A second credential or account created with it | | The window a future unnoticed leak of this value gets | Writes and configuration changes already made | | Nothing else | What the intruder learned about the estate | The right-hand column is why "we rotated it" is never an answer to "were we harmed". If the access let someone take a copy of a dataset, the harm completed on day 1 and the 89-day ceiling bought nothing whatsoever in that incident. If the access paid off gradually — reading a queue, watching what flowed past, widening reach one step at a time — then the ceiling is real value and shortening it saves real work. ## Replacement is not withdrawal Two different actions both get called rotation, and the ceiling comes from only one of them. 1. **Replacement** — a new value is generated and put in front of the consumers that need it. 2. **Withdrawal** — the system that accepts the credential is told to stop accepting the old one. Step 1 on its own leaves the stolen copy working indefinitely; the intruder never cared which value your consumers use, only whether theirs still authenticates. Removing the old value from the store is not withdrawal either — deleting a record where the value was held does not make the system that accepts it refuse it. How two values coexist while consumers move across is its own subject; the point here is that the clock on the ceiling starts when the old value stops authenticating, and the change is not finished before then. ## When the ceiling is not a ceiling The arithmetic assumes the intruder cannot take a fresh copy. If the access that produced the first one is still open — a foothold on a host that reads the value, a place the value is written on its way to the consumer, an output where it is rendered — then day 90 hands over the replacement on a schedule, and the cadence becomes a subscription rather than a bound. Closing the escape path is a precondition of the arithmetic, not a follow-up task. The same applies in a quieter way to a copy nobody withdrew because nobody knew it existed. Every holder still presenting the old value keeps it alive if the accepting system keeps taking it. ## How to answer this in an interview A strong answer does four things in order: - names the number and how it is derived (theft to withdrawal, 89 days here); - says it is a ceiling over the interval, not a measurement of this incident; - separates it cleanly from what was already done with the access; - names the two conditions — the old value actually stopped, and the escape path closed — without which the number is fiction. A weak answer says the intruder is out because the credential was rotated. That is the belief the question exists to test, and it confuses replacing a value with revoking one, and both with containing an intrusion.
- The intruder still holds the foothold that produced the first copy — what does the ninety-day schedule buy then?Close to nothing. The next replacement is delivered to whatever reads the value, and the foothold reads it too, so the cadence refreshes the intruder's access instead of ending it. The ceiling assumes the escape path is closed first; until it is, a shorter cadence only means more frequent handovers.
- The new value is in place and no consumer has errored — is the ceiling in force?Not yet. Nothing erroring proves that consumers can reach the new value, not that the old one has stopped working. The ceiling begins when the system that accepts the credential refuses the old value, which is a separate action against that system, and confirming it is a separate check from watching for errors.
- How would you choose the interval if the ceiling is the only thing you are buying?From how long you would plausibly take to notice misuse and what the access is worth per day of use. Where the access pays off in one act, a shorter interval buys almost nothing and the change cost is pure loss; where the payoff accumulates, the interval is the exposure you are choosing to accept, and it should be written down as such.
saying these in an interview costs you the question
- Rotating the credential undoes the breach it was stolen in
- Installing the new value is the whole of the rotation
- The ninety days is counted from when the leak was noticed
- If it was rotated on schedule, the intruder is out
- Rotation protects the data that was already copied
- Deleting the old value from the store is the same as withdrawing it