diff --git a/KeyUtil.h b/KeyUtil.h
index 23278c1..0f5bc93 100644
--- a/KeyUtil.h
+++ b/KeyUtil.h
@@ -74,9 +74,11 @@
 // responsible for dropping caches.
 bool evictKey(const std::string& mountpoint, const EncryptionPolicy& policy);
 
+// Retrieves the key from the named directory, or generates it if it doesn't
+// exist.  In most cases |keepOld| must be false; see retrieveKey() for details.
 bool retrieveOrGenerateKey(const std::string& key_path, const std::string& tmp_path,
                            const KeyAuthentication& key_authentication, const KeyGeneration& gen,
-                           KeyBuffer* key, bool keepOld = true);
+                           KeyBuffer* key, bool keepOld);
 
 // Re-installs a file-based encryption key of fscrypt-provisioning type from the
 // global session keyring back into fs keyring of the mountpoint.
