This is how you do it when you're not AS childish. You go "here's a model for cybersecurity" and put a price on it. I know they're releasing it to some vendors first, etc. but the lack of a clown spectacle is nice. The whole "it's too dangerous to release!" is complete hogwash. A person can take a hammer, walk out in the street, and we can count how many people he can kill with the hammer before he is stopped. My loc…
OpenAI DayBreak – GPT-5.5-Cyber
101–110 of 184 posts
Re: OpenAI DayBreak – GPT-5.5-Cyber
#102Earlier quoted context omitted.
I'm not sure I follow your logic. Paying for a service does not mean you get access to all potential services a provider offers. Providers can choose to keep some services internal. Silly example: I pay Netflix for their most basic plan, so I get ads. Just because I already pay them money, doesn't mean I have a right to no ads! It also doesn't mean I have a right to 8k streaming; maybe Netflix reserves that for their…
Both companies offer "MAX" or "PRO" plans - and the best models were available to those customers. This new wave of "It's too dangerous for the public" is a new initiative from both companies. I agree with your overall sentiment. Paying for "Claude Mini" doesn't get you "Claude Maximos". However, the overall precedent that the companies have set is that if you pay for the top tier subscription, you get the top tier m…
Re: OpenAI DayBreak – GPT-5.5-Cyber
#103Earlier quoted context omitted.
If you can buy a gun from a weapons manufacturer it doesn't mean they should also allow you to buy a rocket launcher.
First of all, these products are "legal". I think the point is more that we pay for your top subscription but you've decided that a handful of companies that you pick get access to the best of the best now and everyone else has to wait and perhaps they may be allowed access at some point...if deemed worthy. You want the few leading AI companies in the U.S. to work under the model where they (and potentially the U.S.…
Re: OpenAI DayBreak – GPT-5.5-Cyber
#104I don't know what the solution to this is, but I find it somewhat unfair that I pay money to Anthropic, and I pay money to OpenAI, and neither of them will let me use their best models for securing the software I work on. Admittedly Opus 4.8 xhigh does a good job, but are my customers not entitled to have more security from a Fable/Mythos or GPT-5.5-Cyber audit over the codebase? Or I guess the inverse question: why…
Soon, very soon, if you will need something useful, like medical advice, financial advice, you will be told that, well, ok, but you need to pay for an "extended license" that gonna be in thousands of dollars per month, otherwise you need to hire someone who paid that money. The only hope are Chinese models, as Chinese commies are playing a different game as long as they are behind the flagship models (but it will cha…
Re: OpenAI DayBreak – GPT-5.5-Cyber
#105Earlier quoted context omitted.
Why do you think you should have access…? People who pay enterprise API rates also don’t if this makes you feel better (it shouldn’t, you shouldn’t have felt bad in the first place)
I'm not sure I understand what you're arguing for? There are massive companies that collectively profiting off of stolen IP and are now gatekeeping even their paid offerings - surely consumers will rail against this? Personally, I feel very bad and can't wait for Chinese models to continue improving as much as they can prior OpenAI's and Anthropic's IPOs.
This was a problem for 5+ years ago. Nobody cares or at least the majority voice does not care across the world. Cat is out of the bag and there is no way to put it back in.
EDIT: Worth noting that I have long held the belief that if you put data out on the public sidewalk that you should have low to no expectation that it’s IP. It’s how I think about Google Maps data for example. If they want to reap the benefits by not walking it off the a user login than they can feel the pain if folks use that information. Same applies for media that has been bought, Reddit comments or any other datasets.
Re: OpenAI DayBreak – GPT-5.5-Cyber
#106Ok so why I don’t have access to this if I already pay for the max plan? Should I pay a security researcher to run codex on my code? Is this how it is supposed to work? Let’s hope we get some real cyber models that people can actually use from the Chinese without the stupid application forms.
Re: OpenAI DayBreak – GPT-5.5-Cyber
#107Earlier quoted context omitted.
Man, some of you will invent conspiracy theories to justify some deeply cynical fiction. OAI has been more proactive about doing customer KYC than A\. OpenAI, four months ago, started to require users to verify their identity if they flagged their activities on frontier models (gpt-5.3-codex and higher) as risky. Their filters were originally quite coarse and it resulted in a ton of normal tasks being flagged. There…
Oh! So the new openai model is limited to US residents and they use their existing KYC process to verify it? That makes sense if both openai and anthropic have export restrictions on their similar models. If they didn't then it seems like the comment you're replying to may be correct.
Re: OpenAI DayBreak – GPT-5.5-Cyber
#108I don't know what the solution to this is, but I find it somewhat unfair that I pay money to Anthropic, and I pay money to OpenAI, and neither of them will let me use their best models for securing the software I work on. Admittedly Opus 4.8 xhigh does a good job, but are my customers not entitled to have more security from a Fable/Mythos or GPT-5.5-Cyber audit over the codebase? Or I guess the inverse question: why…
> and neither of them will let me use their best models for securing the software I work on.
I mean, are you saying you submitted a Trusted Access application to both OpenAI + Anthropic and they BOTH declined it?I have Verified/Trusted Access on both of them and I don't even work in Cyber.
I filled it out as an individual using my own Org ID and I got accepted to both of them, lol.
Re: OpenAI DayBreak – GPT-5.5-Cyber
#109Earlier quoted context omitted.
I'm no cyber expert, maybe one can weigh in. Are there zero days that only a true genius can discover? Or can a smart-enough model, run over the codebase for enough time, discover them all? Like as we get smarter and smarter models do we expect each new generation to keep finding vulnerabilities, or to plateaue?
A large part of vulnerability analysis is just having the time to crunch through enough possibilities. Expertise and smarts definitely speed this up but there's a lot of just turning the crank until something falls out. Even a relatively dumb model with some good prompting will find vulnerabilities if you ask it to and give it the time and resources to do so.
Been in the security industry a long time as a software engineer. Security research is no different than any other engineering discipline. It is down to the time you are willing to invest and where in the abstraction you focus.
All of this pearl clutching and hand wringing over the capabilities of the models is silly to me. It has much less to do with some magical cybersecurity ability and much more to do with increasing ability of models to stay on task for long horizons. Any passionate engineer will recognize this - if you grind 10,000 hours you will find the solution to most problems, the problem is most people lack the motivation to even start, and are too risk averse to play hacker.
The NSAs claim that all government systems were hacked by mythos and they were shocked by that is farcical. They have been hacked over and over and over by many who took the risk and tried.
It's like they hired a competent red teamer to do internal pen testing for the first time, which we know is absolutely not the case. They have been doing it for years, and almost certainly surfacing the exact same kinds of findings each time, but they haven't been honest with the public about it and can scapegoat mythos now.
Re: OpenAI DayBreak – GPT-5.5-Cyber
#110I don't know what the solution to this is, but I find it somewhat unfair that I pay money to Anthropic, and I pay money to OpenAI, and neither of them will let me use their best models for securing the software I work on. Admittedly Opus 4.8 xhigh does a good job, but are my customers not entitled to have more security from a Fable/Mythos or GPT-5.5-Cyber audit over the codebase? Or I guess the inverse question: why…
How does Anthropic or OpenAI differentiate between the two?
Once you solve that, you can get access to Mythos ;)