
UpTrajectory Review
The security industry has spent years chasing elegant inference when it needed brute-force fact. That is the argument CSO Online advances through an extended historical analogy: the 18th-century longitude problem, where sailors could determine their north-south position precisely but their east-west position only by educated guesswork. The parallel to artificial intelligence detection is deliberate and, for small-business operators wrestling with AI-generated fraud, phishing, and content manipulation, worth taking seriously. The piece uses John Harrison's mechanical clocks against the lunar-distance method to argue that current AI detection tools rely too heavily on probability and pattern-matching when what security demands is verifiable, transportable facts.
For a small-business operator, this framing cuts closer than the usual enterprise-security abstraction. You are already fielding AI-generated vendor emails, deepfaked voice calls purporting to be your bank, and synthetic customer reviews that poison your reputation on platforms you do not control. The detection tools available to you—built into email gateways, review platforms, and fraud services—largely operate on the lunar-distance model. They score likelihoods. They flag probabilities. They tell you this message is 87 percent likely to be AI-generated, which sounds authoritative until you must explain to a customer why you blocked their legitimate inquiry or to your insurer why you acted on a guess. The Harrison model, carried into this domain, would mean detecting not stylistic tells but hard provenance: cryptographic signatures, hardware attestation, supply-chain verification that a human with a specific credential performed a specific action at a specific time.
What makes the piece genuinely useful, and where we are partly skeptical, is its insistence that the problem is never the ocean—it is always the time problem. The security industry has spent billions on better pattern recognition, on training larger models to detect smaller anomalies, on ever more sophisticated inference. The author calls this a category error. We find the argument compelling but incomplete. Harrison's clocks worked because time is a physical constant that can be mechanically preserved. Human intent is not. The gap between provable provenance and practical deployment for a twenty-person business remains enormous, and the piece acknowledges this only in passing. Where we agree absolutely: the current detection market sells probability as certainty, and small operators pay the price in false positives, missed fraud, and compliance exposure.
The downstream effects deserve more attention than the source gives them. If the security industry shifts toward fact-based detection, the cost structure changes radically. Inference scales cheaply; provenance infrastructure does not. Small businesses currently free-ride on platform detection—Gmail's spam filters, Stripe's fraud models, Amazon's review algorithms. A fact-based regime would likely require hardware tokens, verified identity credentials, and auditable transaction logs that impose real friction and real cost. The businesses most exposed to AI fraud are often those least able to absorb that infrastructure. Meanwhile, the largest enterprises, already investing in zero-trust architectures, would consolidate their advantage. The Harrison analogy breaks down here: Parliament's prize democratized navigation, but a provenance-first security model may stratify it.
What to watch: vendor claims that conflate confidence scores with verification. Any detection tool that outputs a percentage without auditable chain-of-custody is selling lunar distance. What to do now: audit your current fraud and authentication stack for where decisions rest on probability versus where they rest on cryptographic or procedural fact. The gap between those two categories is your exposure. The piece ends mid-sentence, suggesting a longer argument about Harrison's subsequent struggles with the British establishment—he was paid only grudgingly, years later—which may parallel how provenance-based security will fight for adoption against incumbent inference vendors. That history, if the author completes it, will be worth following.
The core insight for operators is methodological, not technical. When you evaluate a security claim, ask whether it carries the fact across the ocean or computes a hope against the sky. The distinction determines whether your next security investment builds navigable position or merely prettier uncertainty.
“A guess, however educated, is a probability. When you carry the fact, the answer stops being a matter of odds.” — CSO Online
Takeaway: Audit your fraud stack: flag every tool giving probability scores and demand verifiable provenance where stakes are highest.
Excerpt from the original — CSO Online
For most of the age of sail, a captain could find his latitude in minutes and could not find his longitude at all.
Latitude you could read off the sun. Longitude, your position east to west, offered no such trick. Three weeks into the Atlantic, a navigator knew how far north he was and could only estimate how far along he had come. The estimate was often wrong, and wrong on open water means rocks. After a British fleet was lost on home rocks in 1707, Parliament offered up to 20,000 pounds for anyone who could solve it.
The problem was never the ocean
Longitude is not really a sea problem. It is a time problem.
The Earth turns 15 degrees an hour. Know the exact time at a fixed reference, Greenwich, check it against your local noon, and the gap tells you where you are. The whole problem collapses to one question. Can you carry a single fact, the reference time, across an ocean …