↓Skip to main content

Probably Secure

Probably Secure logo

The AI industry replaced hard constraints with soft likelihoods and called it security. “The model probably won’t do that” is not a security policy. This site documents the engineering patterns that fix the gap between what models can reason about and what infrastructure must enforce.

Recent

The Letter and the Court

·13 mins
In the age of sail, the difference between a privateer and a pirate was a letter of marque — a formal document that scoped authority to a specific enemy, specific waters, and specific timeframe. Captured prizes were adjudicated by courts that evaluated actions against the letter’s terms, not the privateer’s judgment. AI agents carry credentials that say who they are. No credential says what they should be allowed to do right now. Cedar, the first formally verified authorization language, builds the court.

Starving the Fire

·19 mins
Every firefighter learns the fire triangle on day one. Fire requires fuel, heat, and oxygen. Remove any one and the fire cannot sustain. The lethal trifecta for AI agents follows the same structure. Sensitive data, untrusted input, and external communication. The industry is trying to make the fire burn less. The defense is to remove one element. Which element depends on the deployment.

Stamps Without Passports: Identity with Agentic Systems

·11 mins
In 1921, the Soviet government left 800,000 refugees stateless with entry permits from individual countries but no foundational identity binding them together. Fridtjof Nansen solved this with the first internationally recognized identity document for stateless people. AI agents carry the same problem. Three existing identity models fail, the IETF standards solve authentication, and authorization is still your problem.

Trusting the Label

·11 mins
In 1956, Malcolm McLean’s shipping container standardized global trade with no security built into it. The Model Context Protocol is standardizing how AI agents connect to tools with the same choice. The natural comparison is npm, but MCP has a layer npm does not. Tool descriptions enter the context window and execute inside the attention mechanism. The description is the execution.

The Architecture of Inevitability

·16 mins
For fifteen years, the Knoedler Gallery sold $80 million in forged paintings that passed expert authentication. The experts assessed appearance, not provenance. The AI security industry is repeating the pattern with guardrails. Prompt injection and hallucinations share the same root cause in the attention mechanism. The fix is not a better filter. It is a provenance system.