Live data from Hacker News

OpenAI DayBreak – GPT-5.5-Cyber

openai.com

51–60 of 184 posts

Re: OpenAI DayBreak – GPT-5.5-Cyber

#51

I don't know what the solution to this is, but I find it somewhat unfair that I pay money to Anthropic, and I pay money to OpenAI, and neither of them will let me use their best models for securing the software I work on. Admittedly Opus 4.8 xhigh does a good job, but are my customers not entitled to have more security from a Fable/Mythos or GPT-5.5-Cyber audit over the codebase? Or I guess the inverse question: why…

take a look at this bug and the chain required to exploit it:

https://projectzero.google/2021/12/a-deep-dive-into-nso-zero...

https://projectzero.google/2022/03/forcedentry-sandbox-escap...

exploiting vulnerabilities on hardened targets isn't just in a different league from finding them, it is a different sport altogether.

put simply, it's the difference between an integer overflow leading to a sandbox escaping RCE and one that leads to a crash.

Codex Security and 5.5/5.6 are still very good finding vulnerable code -- they will identify and fix unsafe behavior, but they will refuse to help you with exploitation -- they will actively prevent you from taking any steps to weaponize the unsafe behavior that are not required to remediate it. they will err conservative here, but for the most part they will still let you discover and address a wide range and depth of vulnerabilities. you can verify yourself to turn off the most basic safeguards and sign up through a more rigorous process for a spectrum of TAC options.

obviously there is a balance here -- openai wants to empower defenders while at the same time not exposing capabilities to the adversaries that would overwhelm defenders. there is no "right" answer. it is a work in progress. this is an intentional and deliberate decision to provide defenders with a (temporary, dwindling) advantage.

the example i chose was pretty extreme, but the underlying principle -- enable visibility discovery and remediation, but make it difficult to weaponize and defeat countermeasures makes sense given the bigger picture, IMO.

this calm before the storm is not going to last for very long, and defenders need every advantage they can get to get their houses in order before these capabilities are widely commoditized.

Re: OpenAI DayBreak – GPT-5.5-Cyber

#52

No one commenting on the fact that oAI is releasing a Claude Mythos-class model - with apparent 0 restrictions or concerns by the US government, while Anthropic's (their competitor) model has been pulled weeks prior by the administration for 'security' reasons. It certainly has nothing to do with openAI's co-founders donating to the current administrations election fund, are actively supporting the DoW war efforts of…

>No one commenting on the fact that oAI is releasing a Claude Mythos-class model - with apparent 0 restrictions or concerns by the US government We don't know that it is Mythos level, it could very well be at (guardrailed) Fable or below. This is not a wide open distribution, this is only being provided to hand picked partners, similar to how Mythos was distributed (unlike Fable which had wider distribution) The larg…

Isn't Fable just Mythos + prompt guardrails?

Re: OpenAI DayBreak – GPT-5.5-Cyber

#53
I see a lot of knee-jerk comments to this, but I highly recommend running a scan ( https://openai.com/daybreak/codex-security-plugin/#codex-cli ) in your projects so you can evaluate it yourself. It found a real security issue in a project of mine, with very few false-positives.

Its built-in resume mechanism didn't work after it crashed when running out of my 5 hour session limit, but Claude Code was easily able to resume it 5 hours later reading the session logs and https://openai.com/codex/security/scan.sh

Re: OpenAI DayBreak – GPT-5.5-Cyber

#54

I don't know what the solution to this is, but I find it somewhat unfair that I pay money to Anthropic, and I pay money to OpenAI, and neither of them will let me use their best models for securing the software I work on. Admittedly Opus 4.8 xhigh does a good job, but are my customers not entitled to have more security from a Fable/Mythos or GPT-5.5-Cyber audit over the codebase? Or I guess the inverse question: why…

Soon, very soon, if you will need something useful, like medical advice, financial advice, you will be told that, well, ok, but you need to pay for an "extended license" that gonna be in thousands of dollars per month, otherwise you need to hire someone who paid that money.

The only hope are Chinese models, as Chinese commies are playing a different game as long as they are behind the flagship models (but it will change soon, like with cheap Chinese cars) and maybe, finally, Europe will start working on their solutions, instead of regulations.

Re: OpenAI DayBreak – GPT-5.5-Cyber

#55
I read this news as white noise because there is no scenario in which I will be allowed access to this model. First, I happen to be a citizen of a country that is not the USA. What's more shocking is that I'm not even located in the US. Thus in the eyes of OpenAI I do not exist in regard to SOTA security models. Second, I will never ever do KYC with a company that provides text transformation services*. Third, even if I did, I will not be able to pass KYC because the typical KYC requirements are strictly tailored to a certain subset of the world's population and lifestyle choices, tuned by Americans according to their world view. Fourth, even if I pass KYC, my account will be banned by OpenAI immediately on the first prompt because they have close to 1B users and couldn't care less about any single one of them.

(*) which are nothing short of amazing and are changing the world, there's no doubt about that.

Re: OpenAI DayBreak – GPT-5.5-Cyber

#56

Earlier quoted context omitted.

>No one commenting on the fact that oAI is releasing a Claude Mythos-class model - with apparent 0 restrictions or concerns by the US government We don't know that it is Mythos level, it could very well be at (guardrailed) Fable or below. This is not a wide open distribution, this is only being provided to hand picked partners, similar to how Mythos was distributed (unlike Fable which had wider distribution) The larg…

Isn't Fable just Mythos + prompt guardrails?

Correct.

Re: OpenAI DayBreak – GPT-5.5-Cyber

#57

I read this news as white noise because there is no scenario in which I will be allowed access to this model. First, I happen to be a citizen of a country that is not the USA. What's more shocking is that I'm not even located in the US. Thus in the eyes of OpenAI I do not exist in regard to SOTA security models. Second, I will never ever do KYC with a company that provides text transformation services*. Third, even i…

There is so much to unpack here.

> Thus in the eyes of OpenAI I do not exist in regard to SOTA security models.

I'm not seeing anywhere it says it's only limited to the U.S. Only that they had 'ongoing dialogue' with them. Which reads weird to me, how can an ongoing dialogue be past tense? But I digress.

> We’ve had ongoing dialogue with the U.S. government about our cyber approach, including today’s announcements and on our preparation for upcoming model releases.

> Third, even if I did, I will not be able to pass KYC because the typical KYC requirements are strictly tailored to a certain subset of the world's population and lifestyle choices, tuned by Americans according to their world view.

KYC is just that, Know Your Customer, if your 'permitted customers' are security researchers in the industry with a proven identity of employment etc then that is the KYC process, I don't see any issues with that.

> even if I pass KYC, my account will be banned by OpenAI immediately on the first prompt because they have close to 1B users and couldn't care less about any single one of them

Why do you assume this? Are you planning on intentionally trying to do something actively nefarious ? It's such a strange take.

Re: OpenAI DayBreak – GPT-5.5-Cyber

#58

No one commenting on the fact that oAI is releasing a Claude Mythos-class model - with apparent 0 restrictions or concerns by the US government, while Anthropic's (their competitor) model has been pulled weeks prior by the administration for 'security' reasons. It certainly has nothing to do with openAI's co-founders donating to the current administrations election fund, are actively supporting the DoW war efforts of…

Entirely possible but let's give it some time to see if they try to make it GA and if the DoD sends them a letter.

Re: OpenAI DayBreak – GPT-5.5-Cyber

#60
post #57

I read this news as white noise because there is no scenario in which I will be allowed access to this model. First, I happen to be a citizen of a country that is not the USA. What's more shocking is that I'm not even located in the US. Thus in the eyes of OpenAI I do not exist in regard to SOTA security models. Second, I will never ever do KYC with a company that provides text transformation services*. Third, even i…

There is so much to unpack here. > Thus in the eyes of OpenAI I do not exist in regard to SOTA security models. I'm not seeing anywhere it says it's only limited to the U.S. Only that they had 'ongoing dialogue' with them. Which reads weird to me, how can an ongoing dialogue be past tense? But I digress. > We’ve had ongoing dialogue with the U.S. government about our cyber approach, including today’s announcements an…

> how can an ongoing dialogue be past tense?

Easy: it can be considered past tense in case "ongoing dialogue" is a corporatespeak for "f..k you". Which I believe is the case here. But that's an opinion.

> Know Your Customer [..] I don't see any issues with that

This might be the case if you're coming from a standpoint I have mentioned: the American one. This is a world view where everybody have physical paper documents proving residence, every labour effort is arranged in a very specific legal framework, every person have an address in a specific format, every person has one of just a few types of ID documents, etc, etc.

Problem is, the world have vast, vast differences in all of the mentioned areas and KYC companies couldn't care less because they are a business and they make money by KYCing as much people as possible for as little spend as possible. Thus they simply ignore any case that's not mainstream no matter how perfectly legal it is.

Being a digital nomad I cannot pass KYC at the vast majority of online services. My passport is under no sanctions, I do have residency in the first world country, etc., but passing KYC at Persona and others is not possible.

>> my account will be banned by OpenAI immediately > Why do you assume this?

Because of the risk profile. The company has no way of knowing whether "find all security vulnerabilities in this code" is a request from a whitehat or a blackhat hacker. The risk of someone using GPT to hack yet another DeFi project for a hundred millions while mentioning OpenAI is higher than perhaps a million user accounts, let alone a single one.

Post reply on HN