Live data from Hacker News

OpenAI DayBreak – GPT-5.5-Cyber

openai.com

41–50 of 184 posts

Re: OpenAI DayBreak – GPT-5.5-Cyber

#41
post #37

Earlier quoted context omitted.

Did you see how close the non-sheltered available models come? They come quite close. Most people aren't even using them for this purpose, but they could, and this is our reality. This is why your argument fails.

Disagree. @lionkor compared them to a hammer, and @ragequittah is saying they're not like a hammer. The narrow gap between downloadable and frontier models is tangential to this. If you want to expand on the "hammer" metaphor, the downloadable models are a small construction/demolitions firm, and the frontier models are a big construction/demolitions firm. In this analogy, there's no training school or certifications…

> big construction/demolitions firm

Like, e.g. the USACE

Re: OpenAI DayBreak – GPT-5.5-Cyber

#43
post #41
post #37

Earlier quoted context omitted.

Disagree. @lionkor compared them to a hammer, and @ragequittah is saying they're not like a hammer. The narrow gap between downloadable and frontier models is tangential to this. If you want to expand on the "hammer" metaphor, the downloadable models are a small construction/demolitions firm, and the frontier models are a big construction/demolitions firm. In this analogy, there's no training school or certifications…

> big construction/demolitions firm Like, e.g. the USACE

If the USACE was a private military company and local lords sometimes still did direct battle with each other without being told to stop by the king.

Re: OpenAI DayBreak – GPT-5.5-Cyber

#44

I don't know what the solution to this is, but I find it somewhat unfair that I pay money to Anthropic, and I pay money to OpenAI, and neither of them will let me use their best models for securing the software I work on. Admittedly Opus 4.8 xhigh does a good job, but are my customers not entitled to have more security from a Fable/Mythos or GPT-5.5-Cyber audit over the codebase? Or I guess the inverse question: why…

Surely what's coming is them offering to fix your vulnerabilities via higher-margin professional services?

Re: OpenAI DayBreak – GPT-5.5-Cyber

#45
post #24

I don't know what the solution to this is, but I find it somewhat unfair that I pay money to Anthropic, and I pay money to OpenAI, and neither of them will let me use their best models for securing the software I work on. Admittedly Opus 4.8 xhigh does a good job, but are my customers not entitled to have more security from a Fable/Mythos or GPT-5.5-Cyber audit over the codebase? Or I guess the inverse question: why…

I think using open weight models will solve this. I believe they are nearly caught up and much of the gains are in the harnesses or properly orchestration of subqueries. (I'm no expert, just my opinion). When the open weight models catch up, if they don't get lobbied and banned by OpenAi and Anthropic, then you'll be able to use them to properly secure your software.

I'm no cyber expert, maybe one can weigh in.

Are there zero days that only a true genius can discover? Or can a smart-enough model, run over the codebase for enough time, discover them all?

Like as we get smarter and smarter models do we expect each new generation to keep finding vulnerabilities, or to plateaue?

Re: OpenAI DayBreak – GPT-5.5-Cyber

#47

No one commenting on the fact that oAI is releasing a Claude Mythos-class model - with apparent 0 restrictions or concerns by the US government, while Anthropic's (their competitor) model has been pulled weeks prior by the administration for 'security' reasons. It certainly has nothing to do with openAI's co-founders donating to the current administrations election fund, are actively supporting the DoW war efforts of…

Man, some of you will invent conspiracy theories to justify some deeply cynical fiction. OAI has been more proactive about doing customer KYC than A\. OpenAI, four months ago, started to require users to verify their identity if they flagged their activities on frontier models (gpt-5.3-codex and higher) as risky. Their filters were originally quite coarse and it resulted in a ton of normal tasks being flagged. There…

Oh! So the new openai model is limited to US residents and they use their existing KYC process to verify it?

That makes sense if both openai and anthropic have export restrictions on their similar models. If they didn't then it seems like the comment you're replying to may be correct.

Re: OpenAI DayBreak – GPT-5.5-Cyber

#49

No one commenting on the fact that oAI is releasing a Claude Mythos-class model - with apparent 0 restrictions or concerns by the US government, while Anthropic's (their competitor) model has been pulled weeks prior by the administration for 'security' reasons. It certainly has nothing to do with openAI's co-founders donating to the current administrations election fund, are actively supporting the DoW war efforts of…

>No one commenting on the fact that oAI is releasing a Claude Mythos-class model - with apparent 0 restrictions or concerns by the US government

We don't know that it is Mythos level, it could very well be at (guardrailed) Fable or below.

This is not a wide open distribution, this is only being provided to hand picked partners, similar to how Mythos was distributed (unlike Fable which had wider distribution)

The larger question, which I don't see an answer to in this post:

1) was this tested and validated by the US Government?

2) is the list of partners vetted by the US Government?

If This is "mythos-class" AND

   OpenAI approves SK Telecom as a trusted partner ( https://www.wired.com/story/sk-telecom-anthropic-mythos-export-controls/ ) 
OR

   OpenAI did not get approval.
will this be shut down as quick? Otherwise, it is not really a comparable scenario.

Re: OpenAI DayBreak – GPT-5.5-Cyber

#50
post #24

Earlier quoted context omitted.

I think using open weight models will solve this. I believe they are nearly caught up and much of the gains are in the harnesses or properly orchestration of subqueries. (I'm no expert, just my opinion). When the open weight models catch up, if they don't get lobbied and banned by OpenAi and Anthropic, then you'll be able to use them to properly secure your software.

I'm no cyber expert, maybe one can weigh in. Are there zero days that only a true genius can discover? Or can a smart-enough model, run over the codebase for enough time, discover them all? Like as we get smarter and smarter models do we expect each new generation to keep finding vulnerabilities, or to plateaue?

A large part of vulnerability analysis is just having the time to crunch through enough possibilities. Expertise and smarts definitely speed this up but there's a lot of just turning the crank until something falls out. Even a relatively dumb model with some good prompting will find vulnerabilities if you ask it to and give it the time and resources to do so.
Post reply on HN