Live data from Hacker News

OpenAI DayBreak – GPT-5.5-Cyber

openai.com

91–100 of 184 posts

Re: OpenAI DayBreak – GPT-5.5-Cyber

#92
post #85

Earlier quoted context omitted.

> The company has no way of knowing whether "find all security vulnerabilities in this code" is a request from a whitehat or a blackhat hacker That's what KYC is for. > This might be the case if you're coming from a standpoint I have mentioned: the American one. I'm not in the US, nor America for that matter, I'm in the EU. > Problem is, the world have vast, vast differences in all of the mentioned areas and KYC comp…

>> The company has no way of knowing > That's what KYC is for. No, KYC has nothing to do with that problem. KYC doesn't help at all here. > I'm not in the US, nor America for that matter, I'm in the EU. Same here.

> No, KYC has nothing to do with that problem. KYC doesn't help at all here.

that's a bold statement. how does it not help solve the problem? what is a better solution?

Re: OpenAI DayBreak – GPT-5.5-Cyber

#93

No one commenting on the fact that oAI is releasing a Claude Mythos-class model - with apparent 0 restrictions or concerns by the US government, while Anthropic's (their competitor) model has been pulled weeks prior by the administration for 'security' reasons. It certainly has nothing to do with openAI's co-founders donating to the current administrations election fund, are actively supporting the DoW war efforts of…

Conspiracy theory. You should be shamed for this idea.

Mythos is a serious model; the NSA said it compromised them in hours.

This is a marketing article.

Re: OpenAI DayBreak – GPT-5.5-Cyber

#94

I don't know what the solution to this is, but I find it somewhat unfair that I pay money to Anthropic, and I pay money to OpenAI, and neither of them will let me use their best models for securing the software I work on. Admittedly Opus 4.8 xhigh does a good job, but are my customers not entitled to have more security from a Fable/Mythos or GPT-5.5-Cyber audit over the codebase? Or I guess the inverse question: why…

If you can buy a gun from a weapons manufacturer it doesn't mean they should also allow you to buy a rocket launcher.

First of all, these products are "legal". I think the point is more that we pay for your top subscription but you've decided that a handful of companies that you pick get access to the best of the best now and everyone else has to wait and perhaps they may be allowed access at some point...if deemed worthy.

You want the few leading AI companies in the U.S. to work under the model where they (and potentially the U.S. gov't) gets to decide who gets access to what compute? If you are fine paying into that model, then good for you...just a matter of time before they cut you off and you have no ramifications.

Re: OpenAI DayBreak – GPT-5.5-Cyber

#95

Earlier quoted context omitted.

>> The company has no way of knowing > That's what KYC is for. No, KYC has nothing to do with that problem. KYC doesn't help at all here. > I'm not in the US, nor America for that matter, I'm in the EU. Same here.

> No, KYC has nothing to do with that problem. KYC doesn't help at all here. that's a bold statement. how does it not help solve the problem? what is a better solution?

> how does it not help solve the problem

How does it? Online KYC is a procedure to verify someone's documents and face. And that's it. What does it have to do with the actual usage of the OpenAI account and the code that is being examined with AI?

Re: OpenAI DayBreak – GPT-5.5-Cyber

#96

Earlier quoted context omitted.

I'm not sure I follow your logic. Paying for a service does not mean you get access to all potential services a provider offers. Providers can choose to keep some services internal. Silly example: I pay Netflix for their most basic plan, so I get ads. Just because I already pay them money, doesn't mean I have a right to no ads! It also doesn't mean I have a right to 8k streaming; maybe Netflix reserves that for their…

Both companies offer "MAX" or "PRO" plans - and the best models were available to those customers. This new wave of "It's too dangerous for the public" is a new initiative from both companies. I agree with your overall sentiment. Paying for "Claude Mini" doesn't get you "Claude Maximos". However, the overall precedent that the companies have set is that if you pay for the top tier subscription, you get the top tier m…

Just like when you buy a top of the line camera or car, and then they release a new one, you are entitled to the now-top-of-the-line camera or car.

What the heck come on.

Re: OpenAI DayBreak – GPT-5.5-Cyber

#97

Earlier quoted context omitted.

Maybe if Anthropic haven't called it too dangerous for public things could be different?

We should be basing public policy on facts not marketing language.

Why? You can’t yell fire in a crowded place, but “this is going to destroy the world, sign up now” is okay?

Most things should be fact based, but you also should have limits to your marketing

Re: OpenAI DayBreak – GPT-5.5-Cyber

#98

No one commenting on the fact that oAI is releasing a Claude Mythos-class model - with apparent 0 restrictions or concerns by the US government, while Anthropic's (their competitor) model has been pulled weeks prior by the administration for 'security' reasons. It certainly has nothing to do with openAI's co-founders donating to the current administrations election fund, are actively supporting the DoW war efforts of…

Interesting beside the time when Anthropic were banned for not allowing the MoW to use claude to kill people, then OpenAI come in and swoop up the contract.

That's not what happened.

DoD signed a contract with Anthropic that said it can't use Claude 1) to run a fully-autonomous killchain or 2) to surveil Americans.

DoD then decided they did not want to abide by the contract they signed, and they've since launched a pressure campaign to coerce Anthropic into reneging on the terms they already agreed to.

Re: OpenAI DayBreak – GPT-5.5-Cyber

#99

Earlier quoted context omitted.

We should be basing public policy on facts not marketing language.

Why? You can’t yell fire in a crowded place, but “this is going to destroy the world, sign up now” is okay? Most things should be fact based, but you also should have limits to your marketing

Did Anthropic say "this is going to destroy the world, sign up now"? The details matter quite a lot actually in free speech cases.

Should a nuclear energy startup that says "nuclear weapons are very dangerous and should be regulated" be liable to have its assets frozen?

Re: OpenAI DayBreak – GPT-5.5-Cyber

#100

Earlier quoted context omitted.

> No, KYC has nothing to do with that problem. KYC doesn't help at all here. that's a bold statement. how does it not help solve the problem? what is a better solution?

> how does it not help solve the problem How does it? Online KYC is a procedure to verify someone's documents and face. And that's it. What does it have to do with the actual usage of the OpenAI account and the code that is being examined with AI?

> The company has no way of knowing whether "find all security vulnerabilities in this code" is a request from a whitehat or a blackhat hacker

the system in place to prevent unauthorized abuse. by default, the guardrails are conservative. to reduce the guardrails you can jump through a progressive series of hoops to establish whether or not you have a valid use case. the entrypoint for establishing your use case is verifying your identity and background. if you don't want to do this, you are free to use Codex Security to identify and fix vulnerabilities, it is quite good at this. the harness and model are already evaluating the usage of the account and the nature of the code being examined and actions requested. but the again, the guardrail thresholds will be very conservative for anonymous users.

what is your proposal?

Post reply on HN