Specifically, the hypothesis is that dishonest miners are contributing hashes but stealing blocks from various pools. If pools don't have a way of detecting such behavior, then what you would see is some longer-established pools starting to see consistent lower luck. New small pools such as kano would see relatively higher luck until the dishonest miners start infiltrating them as well. In other words, the anecdotal data on "luck" of different pools is consistent with there being dishonest miners out there.
So what is or can be done to detect and/or block such miners? Certainly over time you can run statistical tests that would identify miners with below-average luck. At some point that becomes statistically significant, but a smart dishonest player could keep changing accounts to make this hard to detect.
Or more realtime tricks could be done by the pool to detect and kill bad players up front.