RC RANDOM CHAOS

LLMs turned fluency into a forged credential

Perceived intelligence is a sender-controlled signal, not identity. Treating fluency as authorization is the exposure social engineers now produce on demand.

· 8 min read
LLMs turned fluency into a forged credential

People grant trust to whoever sounds intelligent. Vocabulary, fluent domain language, confident phrasing, the right credentials placed in the right order. None of those are identity. None of those are intent. They are surface markers, and every one of them can be produced on demand by someone who is neither competent nor trustworthy. The security question is not whether a message sounds smart. The security question is whether sounding smart was ever a valid reason to lower a verification threshold. It was not.

Perceived intelligence functions as an access token in human decision-making. When the token is present, scrutiny stops. The sender who writes like a senior engineer is treated as a senior engineer. The caller who speaks the internal vocabulary is treated as an insider. The message that reads as precise and informed is treated as legitimate. This is the exposure. Intelligence is being used as an authorization signal, and it was never an authorization signal. It maps to no account, no role, no verified relationship. It is presentation, and presentation is being read as proof.

Your intellectual fly is open. The signals you use to decide who is smart, and therefore who is safe, are visible, predictable, and repeatable. You are broadcasting the exact criteria an attacker has to satisfy to pass. Match the register, match the jargon, match the confidence, and the trust decision resolves in the attacker’s favor before any claim is verified. Like an open fly, the exposure is obvious to everyone except the person carrying it, and it stays open precisely because the carrier assumes it is closed.

The operating assumption under attack is that intelligence correlates with legitimacy. That competence in a subject implies standing in that subject. That an email written in clean, technical, senior language came from a clean, technical, senior source. That confidence and precision are byproducts of authority rather than inputs that can be typed. Every trust interaction that relies on this assumption is delegating an identity decision to a proxy that measures how the counterparty sounds, not who the counterparty is.

The observable behavior is a verification threshold that moves with perceived competence. A clumsy, misspelled request gets challenged. A fluent, technically fluent request gets actioned. The payload can be identical. The distinguishing variable is the reader’s assessment of the sender’s intelligence, and that assessment is doing work it was never validated to do. The control that is supposed to gate the action, confirm the identity, confirm the request through a second channel, quietly does not fire when the sender clears the intelligence bar. The gate is present in policy and absent in behavior.

What failed is a delegated trust decision. The proxy is a single implicit question: does this person seem to know what they are talking about. That proxy is never enforced against identity, never checked against a directory, never confirmed out of band. It runs entirely on the surface of the communication. A control that only measures presentation cannot separate a real expert from a convincing impostor, because both produce the same surface. If the signal cannot distinguish the two cases, it is not a control. It is a preference.

What changed is the cost of manufacturing the signal. Fluent, technically precise, credentialed-sounding language is now generated at scale, in seconds, in any register a target expects. The output that a reader interprets as this person is smart, and therefore safe, no longer requires the writer to be smart, informed, or even a specific person. Production of the intelligence signal has been decoupled from possession of intelligence. The marker survives. The thing it was supposed to indicate does not have to be present.

The heuristic worked, weakly, because faking convincing competence used to carry a cost. Producing text that read as genuinely expert took time, knowledge, and effort, which gave the signal some predictive value, a rough floor under it. That floor is removed. The register, the jargon, the confident structure, the domain-specific detail can be assembled by anyone at near-zero cost and delivered at volume. The correlation that made the shortcut partially reliable is gone. The shortcut is still running in every reader who has not been told it stopped working.

This is not a more advanced phishing email, and it should not be filed as one. It is the removal of the single friction that made sounds competent a partially useful filter. Attackers no longer need to be convincing in the sense of understanding the subject. They need to appear intelligent, and appearing intelligent is now free, fast, and infinitely repeatable. The perception of intelligence has been converted from a scarce, weakly earned signal into a manufactured, on-demand input to your trust decisions. Everything downstream that still treats it as earned is now exposed.

The failure is substitution, not addition. Perceived competence does not raise confidence on top of a completed identity check. It stands in place of the check. The reader receives a message, extracts the surface attributes, register, vocabulary, structure, stated credentials, and produces a competence score. That score then occupies the slot where identity verification was supposed to run. The action proceeds on the score. The verification never executes. Observed from outside, the system actions a fluent request and holds a clumsy one, with no identity confirmation performed in either case. The only variable that moved was the reader’s estimate of the sender’s intelligence.

Every attribute in that competence score is authored by the sender. The register is chosen. The vocabulary is selected. The confidence is typed. The credentials are stated, not verified against any source. The reader is measuring properties that exist entirely inside the message, and the message is written by the party under evaluation. This is a closed loop. The attacker supplies the claim and supplies the evidence used to judge the claim. No external reference is consulted. A control that grades a sender using only material the sender produced is not testing the sender. It is transcribing the sender’s own assertion and returning it as a verdict.

The threshold moves in the wrong direction. As perceived intelligence rises, scrutiny falls. The sender who sounds most authoritative receives the least verification. Stated as a control, this is inverted: the strongest presentation buys the widest access. An attacker reading this behavior does not need to defeat the verification step. The verification step defeats itself the moment the sender clears the intelligence bar, and the sender sets the height of that bar by choosing how to write. The gate is not bypassed by force. It is opened from the inside by the exact signal it was trusting.

This is one instance of a single, repeatable failure class. Any attribute that the evaluated party can produce cannot function as an authorization signal. If the sender controls the signal, the signal proves nothing about the sender. Perceived intelligence is producible, so it authorizes nothing. The specific content of the signal is not the vulnerability. The vulnerability is the category: trust decisions bound to producible surface rather than to verified identity.

The same mechanism runs under signals that look unrelated. A spoofed display name is read as the person it names. A forged caller ID is read as the number it shows. A copied logo and letterhead are read as the organization they depict. A uniform is read as the role it resembles. In every case the receiver measures an attribute, and in every case the sender controls that attribute. Perceived intelligence sits in the same class. It is a sender-controlled surface signal read as identity. The reader is not doing anything different when they trust a senior-sounding email than when they trust a familiar name in a From field. Both grant access on producible presentation.

The class was survivable while production carried cost. Forging a convincing letterhead took effort. Sounding like a domain expert took knowledge. That cost put a weak floor under the signal and kept volume low. Cost is the only thing that ever made these signals partially reliable, and cost is what has been removed. Fluent, credentialed, domain-precise language is now produced at scale, on demand, in any register a target expects. The floor is gone and the volume is unbounded. A weak heuristic that survived on scarcity is now running against an attacker who can manufacture the signal for free and send it without limit. The pattern did not change. Its cost structure did, and that is enough to convert a tolerable weakness into the primary path in.

Perceived intelligence must be removed as an input to trust. The verification threshold has to be constant. It does not rise for a clumsy sender and fall for a fluent one. It fires the same on both, because how a message sounds carries no information about who sent it. A control that only challenges the sender who sounds wrong is not a control against this attack. It is a filter for low-effort attackers and an open door for competent ones.

Identity is the boundary, and identity is confirmed against something the sender does not control. Out of band. Against a directory, a known channel, a credential the reader can independently check. The confirmation must execute regardless of how expert the request reads, and it must execute before the action, not after the impact. If the check can be skipped because the sender cleared an intelligence bar, the check does not exist. Policy that names a verification step which behavior does not perform is not a control. It is a description of a control the organization does not have.

Sounding smart was never authorization. It mapped to no account, no role, no verified relationship, and it was tolerated only because faking it used to cost something. It no longer costs anything. The signal is manufactured, free, and infinite, and everything downstream that still reads it as earned is exposed by default. The fly stays open for exactly one reason: the carrier assumes it is closed. Stop grading the sender on the test the sender wrote. Bind trust to identity or accept that anyone who can type like an expert already has your access.

Share

Keep Reading

Stay in the loop

New writing delivered when it's ready. No schedule, no spam.