Detection's Real Edge: Owning the Facts
An essay argues that AI-era detection succeeds not by better inference but by carrying authoritative facts attackers must guess.
In the age of sail, a captain could determine latitude in minutes and could not determine longitude at all. Latitude was readable from the sun. Longitude, the east-to-west position, offered no such trick. Three weeks into an Atlantic crossing, a navigator knew how far north he was and could only estimate how far along he had come. An estimate that was often wrong, and wrong on open water means rocks. After a British fleet was lost on home rocks in 1707, Parliament offered up to 20,000 pounds for anyone who could solve it.
That historical episode, recounted in a CSOonline essay, serves as the frame for an argument about AI-era detection. The essay is not a news report. It is an argument, and its central claim is that the contest between attackers and defenders now turns on what each side can carry as fact rather than what each side can infer.
The Problem Was Never the Ocean
Longitude is not really a sea problem, the essay states. It is a time problem. The Earth turns 15 degrees an hour. Know the exact time at a fixed reference, Greenwich, check it against your local noon, and the gap tells you where you are. The whole problem collapses to one question: can you carry a single fact, the reference time, across an ocean without losing it?
The prestigious answer was the lunar distance method. Measure the angle between the moon and the stars, then calculate against printed tables to derive the time. It was elegant and rigorous, according to the essay. And it was inference. You looked at the sky and computed a hope.
The essay presents this as the core distinction that matters for security today. Inference, however sophisticated, remains a probability. Carrying a fact changes the nature of the answer.
The Carpenter Who Refused the Premise
John Harrison did something different, the essay recounts. A self-taught carpenter from a Yorkshire village, his move was not to guess the time more cleverly. It was to carry it. He set out to build a clock so indifferent to a pitching deck, heat, cold, salt, and damp that it could hold Greenwich time across months at sea. Do that, and longitude becomes arithmetic. Not a calculation of where you probably are. A statement of where you are.
In 1761, his fourth timekeeper sailed to Jamaica, and after 81 days at sea it had lost five seconds. That meant a longitude error of about one nautical mile, according to the essay.
The distinction matters, the essay argues. A guess, however educated, is a probability. When you carry the fact, the answer stops being a matter of odds. There was still a problem, the essay notes. Harrison had made one magnificent object by hand. The navy needed something every ship could carry cheaply and at scale. Chronometers remained expensive, so lunar tables stayed in use long after Harrison proved the idea. The fact only truly won when reliable timekeepers could travel onto every deck.
The AI Era Is a Longitude Problem
Attackers and defenders are now reaching for the same engines, the essay states. The reasoning models that can write a flawless lure are the same class of models that can read one. When both sides have comparable instruments, the contest increasingly comes down to what you feed them.
For most of security's history, we did what the astronomers did, according to the essay. We got better at inference. Better anomaly scoring, better reputation systems, better models of what bad behavior looked like before. More sophisticated ways of reading the sky. Attackers operate largely the same way, the essay says. They scrape your org chart, guess who signs the wire, assume which domains belong to you and harvest what normal looked like months ago. Their picture is external, often stale and rarely confirmed. They are reading your stars.
Defenders can carry facts the attacker has to guess at, the essay argues: who actually approves a payment and whether it takes two signatures, the 99 domains you own that an outsider might flag as strangers, the vendor that is real and the one that never existed.
What Ground Truth Actually Looks Like
That advantage is not absolute, the essay concedes. Attackers get inside through stolen passwords, compromised mailboxes and breached suppliers. But getting inside costs them, and even then, they are moving against facts they cannot fully see or reliably keep current. For 30 years, the asymmetry ran their way because they only had to be right once. Ground truth is how the price starts to run the other way.
The essay offers a concrete scenario. Consider a wire request from the CFO. The grammar is perfect, the tone is right, the thread looks real and it clears every reputation and anomaly check because nothing about it appears unusual. What kills it is a fact. The person named as approver is not the approver of record for that account, and the reply-to domain is not one of the 99 you own. A system carrying your ground truth does not need to decide whether the email looks strange. It can ask whether the message contradicts something you already know to be true.
Then comes the hard part, the essay says. Ground truth decays. Approvers change; domains sprawl and business units add vendors nobody logs. A fact you stop maintaining becomes a confident guess in better clothes. Keeping those records true is the modern equivalent of getting the chronometer onto every ship and keeping every one wound.
The Limits of the Analogy
None of this produces a system that cannot be fooled, the essay states. It produces one that is fooled far less and, for anyone who has to answer for a decision later, one whose reasoning can be read back. Owning the truth is the idea. Keeping it true is the work.
For 300 years the best navigators alive guessed their way across the ocean, and good ones still ran aground, the essay notes. The attackers at your gate are doing much the same thing, inferring your world from the outside and computing a plausible version of it. Guesses have been good enough to wreck fleets. The question the essay poses is whether your defenses are still reading the stars beside them or carrying the fact.
If you want to know where to start, the essay says, start with the fact your attacker most has to guess: who in your company can actually move money.
Why It Matters
The essay's argument has a practical edge for security teams drowning in detection tooling. If the central claim holds, then spending more on model sophistication may yield less than the unglamorous work of maintaining authoritative records: current approvers, owned domains, real vendors. The essay frames this as the modern equivalent of getting chronometers onto every ship. That is an inference from the essay's own analogy, not a tested outcome. The source does not report breach data, vendor benchmarks, or vulnerability disclosures to back it. It is an argument, and it should be read as one.
But the argument's logic is worth taking seriously. If attackers are indeed inferring your world from the outside while you hold facts they cannot see, then the maintenance of those facts becomes a security control in its own right. The essay does not claim this is easy or complete. It claims it shifts the odds. For defenders who have watched detection budgets rise without a corresponding drop in successful intrusions, that is at least a different place to look.
Sources
- CSO Online Original source
Continue Reading
LiteLLM's Default Admin Key Exposed
A Wiz Research scan found 294 exposed LiteLLM gateways accepted the example admin key sk-1234, granting access to stored provider credentials.
A Forgotten Admin Login, 4,000 Records
A dental practice kept a contractor's secret admin account active for at least three years, exposing thousands of patient records.
Defender Bypass Chain Grows Again
Nightmare Eclipse drops ShieldCrash, a fresh Microsoft Defender zero-day that bypasses incomplete fixes for the ShieldBreak exploit.