Programming Masters
Explained / Security
Explained · The full loop

The life of a secret

The two pages before this one show that authentication is just maths over a secret. Which means the whole game is what happens to that secret from the moment it is created to the moment it is destroyed. This page follows that loop, shows where it gets attacked, what changed now that AI agents hold secrets too, and how a company proves it is handling them properly.

Nothing to paste hereVendor neutralMaps to SOC 2 and ISO 27001

First, what is a secret?

Anything that, if copied, lets someone else be you or your system. The four you met on this site, and the one you meet every day.

TOTP seed20 bytes, shared

Both your phone and the server hold it. Whoever copies it makes valid codes forever. Symmetric: two copies exist by design.

Passkey private key32 bytes, never shared

Only your device holds it. The server holds a public key that cannot be used to sign. Asymmetric: one copy exists.

Session tokenRandom string, short-lived

What the server hands you after login. Stealing it skips authentication entirely. This is what most real attacks go after.

API key or agent credentialNon-human identity

A secret used by software, not a person. Today that increasingly means an AI agent. Nobody feels it when it is copied.

One loop, five stages, three points of view

Click a stage. The left lane is how it gets attacked, the middle is what you personally do, the right is what a company must do and be able to prove.

From our assurance practiceOur team has directed SOC 1 and SOC 2 examinations for hyperscale cloud providers and led ISO 27001 programmes for regulated enterprises across the Gulf, Europe and North America. These are the questions we ask on every engagement.
More explained