Live data from Hacker News

OpenAI DayBreak – GPT-5.5-Cyber

openai.com

151–160 of 184 posts

Re: OpenAI DayBreak – GPT-5.5-Cyber

#151

I don't know what the solution to this is, but I find it somewhat unfair that I pay money to Anthropic, and I pay money to OpenAI, and neither of them will let me use their best models for securing the software I work on. Admittedly Opus 4.8 xhigh does a good job, but are my customers not entitled to have more security from a Fable/Mythos or GPT-5.5-Cyber audit over the codebase? Or I guess the inverse question: why…

At least on their benchmark, the regular, public GPT-5.5 is basically at Mythos level already. (2% difference on CyberGym)

They didn't test Opus 4.8, but it probably isn't very far behind.

Re: OpenAI DayBreak – GPT-5.5-Cyber

#152
post #121
post #113

Earlier quoted context omitted.

More importantly who gets to decide good or bad? Remember all of these models are based on unimaginable levels of copyright infringement. Is OpenAI a bad actor, that they use their models to infringe on the rights of others? This isn't a moral argument. This is all about power and money, not good or bad. That includes the Mythos ban. Good vs bad actors is political theater designed to distract from what's actually go…

> unimaginable levels of copyright infringement This isn't how copyright works. The models don't wholesale encode literal information from original works and are substantive transformations. Now, you yourself as a user can use the models and weights to infringe on a copyright.

I think parent poster was referring to the open secret that the early models were trained on massive collections of pirated novels and textbooks.

Re: OpenAI DayBreak – GPT-5.5-Cyber

#153
post #50

Earlier quoted context omitted.

A large part of vulnerability analysis is just having the time to crunch through enough possibilities. Expertise and smarts definitely speed this up but there's a lot of just turning the crank until something falls out. Even a relatively dumb model with some good prompting will find vulnerabilities if you ask it to and give it the time and resources to do so.

Completely agree. Its all about time spent. Been in the security industry a long time as a software engineer. Security research is no different than any other engineering discipline. It is down to the time you are willing to invest and where in the abstraction you focus. All of this pearl clutching and hand wringing over the capabilities of the models is silly to me. It has much less to do with some magical cybersecu…

> Any passionate engineer will recognize this - if you grind 10,000 hours you will find the solution to most problems, the problem is most people lack the motivation to even start, and are too risk averse to play hacker.

This. I'd love to spend my whole day hacking stuff, but I need to pay my bills.

Now with AI tooling my late night/weekend hobby hacking stuff is at least getting done. I'm definitely progressing with things that I began 2 years ago and I had to stop as other life priorities took over.

Re: OpenAI DayBreak – GPT-5.5-Cyber

#154
"trusted defenders" sounds really Orwellian. Reminds me of EU's "trusted flaggers": https://digital-strategy.ec.europa.eu/en/policies/trusted-fl...

I don't trust any of these people. Meanwhile I'm paying ChatGPT and Claude and can't use their top-tier levels because they assume I'm some security risk/terrorist.

Local AI is our only hope.

Re: OpenAI DayBreak – GPT-5.5-Cyber

#155
post #147

Earlier quoted context omitted.

> No, KYC has nothing to do with that problem. KYC doesn't help at all here. that's a bold statement. how does it not help solve the problem? what is a better solution?

How does KYC tell a company whether you have bad intentions or not? Let's say you work in a consultancy doing security research. On paper that looks good right? How easy would it be for criminal orgs to setup legitimate looking fronts to pass these KYC checks?

see my downthread post. kyc is the first step in the process, not the last. without verifying identity, none of the other steps can take place

Re: OpenAI DayBreak – GPT-5.5-Cyber

#156

I don't know what the solution to this is, but I find it somewhat unfair that I pay money to Anthropic, and I pay money to OpenAI, and neither of them will let me use their best models for securing the software I work on. Admittedly Opus 4.8 xhigh does a good job, but are my customers not entitled to have more security from a Fable/Mythos or GPT-5.5-Cyber audit over the codebase? Or I guess the inverse question: why…

The problem is even worse than that. OpenAI and Anthropic have your source code and superior knowledge of its vulnerabilities. All you can do is hope that they won't one day use it against you.

To what end?

Re: OpenAI DayBreak – GPT-5.5-Cyber

#157

Earlier quoted context omitted.

> and neither of them will let me use their best models for securing the software I work on. I mean, are you saying you submitted a Trusted Access application to both OpenAI + Anthropic and they BOTH declined it? I have Verified/Trusted Access on both of them and I don't even work in Cyber. I filled it out as an individual using my own Org ID and I got accepted to both of them, lol.

So I got turned off the OpenAI form because it’s pretty heavily geared towards “enterprise” which I’m not. But I’ll have a stab at it later. What’s the equivalent form for Anthropic please? The closest I got from Google was Claude Security’s “contact sales.”

Equivalent of Trusted Access for Anthropic is "CVP" (Cyber Verification Program)

https://support.claude.com/en/articles/14604842-real-time-cy...

Re: OpenAI DayBreak – GPT-5.5-Cyber

#158
post #87

Earlier quoted context omitted.

I'm not sure I understand what you're arguing for? There are massive companies that collectively profiting off of stolen IP and are now gatekeeping even their paid offerings - surely consumers will rail against this? Personally, I feel very bad and can't wait for Chinese models to continue improving as much as they can prior OpenAI's and Anthropic's IPOs.

I’m not arguing for anything, actually. The ‘fair’ ship has sailed, even if the pirates somehow get shut down (which would be suicide by USG, won’t happen, national security issue), open Chinese models are not even hiding the fact that they distill from the frontier US labs, thus benefiting indirectly from the stolen content. Note I don’t particularly like the ‘stolen’ word here as I don’t like when the music and fil…

> I don’t particularly like the ‘stolen’ word here

Except that's the standard that we've measured everyone with up until the LLM/generative tech boom. I don't see why the benchmarks should change now. I realise my argument doesn't move reality but that doesn't mean we shouldn't call a spade a spade. Said companies carried out theft (or copyright infringement if you prefer) at industrial scale which is far more reprehensible crime against humanity than anything the individuals we think of as "digital pirates" have committed.

> open Chinese models are not even hiding the fact that they distill from the frontier US labs

The difference is they return to the same system that they feed from (indirectly); people get access to model weights even if the entire model isn't open source. The same can't be said for OpenAI, Anthropic, Google etc (who also benefit from Chinese models and train on them).

Sure, the alternatives aren't a panacea of fairness but I'd much rather advocate for and support the thieves who give me a better deal if my choice is limited to thieves. Especially if thieves aren't hostile to their customers like Anthropic is (which is why I replied to you in the first place).

Re: OpenAI DayBreak – GPT-5.5-Cyber

#159

"trusted defenders" sounds really Orwellian. Reminds me of EU's "trusted flaggers": https://digital-strategy.ec.europa.eu/en/policies/trusted-fl... I don't trust any of these people. Meanwhile I'm paying ChatGPT and Claude and can't use their top-tier levels because they assume I'm some security risk/terrorist. Local AI is our only hope.

Why not stop paying for ChatGPT and Claude, then?

Like, seriously, while you can, invest in your own stack or find cloud alternatives.

If you actually want to use these products, the easiest way you will contribute to changing their money-grubbing minds about their policies and offerings, is to stop giving them yours.

Peace of mind and control of your destiny is worth a bit of cash. And there's seemingly little risk of any kit you buy radically depreciating in cost.

I am still really cynical about all of this BS but I must say I am fully impressed by the diligence and quality of some of the open source tooling — Unsloth Studio, Opencode, Paseo, Pi, etc.

And I look at it and think: putting aside local models (and I am not sure you should, even now), is this stuff really so inferior that it's worth risking a critical dependency on a commercial cloud product that might get switched off with no notice?

Re: OpenAI DayBreak – GPT-5.5-Cyber

#160

Earlier quoted context omitted.

I'm not sure I understand what you're arguing for? There are massive companies that collectively profiting off of stolen IP and are now gatekeeping even their paid offerings - surely consumers will rail against this? Personally, I feel very bad and can't wait for Chinese models to continue improving as much as they can prior OpenAI's and Anthropic's IPOs.

And the Chinese models rip IP just like everyone else before them. Your argument is moot. This was a problem for 5+ years ago. Nobody cares or at least the majority voice does not care across the world. Cat is out of the bag and there is no way to put it back in. EDIT: Worth noting that I have long held the belief that if you put data out on the public sidewalk that you should have low to no expectation that it’s IP.…

> And the Chinese models rip IP just like everyone else before them.

The difference is the Chinese models return to the same system that they feed from (indirectly); people get access to model weights even if the entire model isn't open source. The same can't be said for OpenAI, Anthropic, Google etc (who also benefit from Chinese models and train on them).

Further, Chinese models are significantly cheaper and the comapnies aren't hostile to their customers.

> Worth noting that I have long held the belief that if you put data out on the public sidewalk that you should have low to no expectation that it’s IP.

Except your beliefs aren't the cornerstone of modern jurisprudence. Why are models able to reliably produce replicas of Ghibli movies which go well beyond any example you listed?

Post reply on HN