Live data from Hacker News

Codex Security

github.com

121–130 of 257 posts

Re: Codex Security

#121
post #39

Earlier quoted context omitted.

This looks great, thanks for open-sourcing it! How does it deal with the current guardrails 5.6 Sol has on finding vulnerabilities? When I use it in the Codex app it would sometimes say it found a vulnerability, but it cannot tell me what it is.

Thanks! You've run into a real limitation: the CLI doesn't bypass the model's cybersecurity guardrails. If GPT-5.6 Sol finds a vulnerability but refuses to explain it, switching from the Codex app to the CLI won't automatically fix that. For authorized defensive work, Trusted Access for Cyber (TAC1/Daybreak) can reduce refusals depending on the model and the account or organization where access is provisioned. It isn…

>> For authorized defensive work, Trusted Access for Cyber (TAC1/Daybreak) can reduce refusals

Or perhaps a better option is to use something like Kimi K3 and cancel the GPT subscription altogether.

Re: Codex Security

#122
post #100

Earlier quoted context omitted.

They're only discovering the security flaws that exist. Would you rather them not be exposed and corrected? To "Slow the testing down"?

I think his point is that AI is really good at finding vulnerabilities.

I think his point was AI is really good at introducing vulnerabilities?

Re: Codex Security

#124

Earlier quoted context omitted.

> Have experience shipping production full-stack products across modern web frontends and backend services. I'm amazed that the requirements are so low (or at least this vague) for jobs at companies like these. Has anyone else had the experience of going to an interview and feeling like you were never asked any qualifying questions? All the questions were easy, your answers were straightforward, you "got them right",…

This sounds like it’s just an app development role, not a security analysis position, so I’m not sure what your complaint is.

> just an app development role

Maybe this is part of the problem

Re: Codex Security

#125

Earlier quoted context omitted.

> Have experience shipping production full-stack products across modern web frontends and backend services. I'm amazed that the requirements are so low (or at least this vague) for jobs at companies like these. Has anyone else had the experience of going to an interview and feeling like you were never asked any qualifying questions? All the questions were easy, your answers were straightforward, you "got them right",…

If you didn't already know, jobs at highly competitive companies tend to have vague job requirements because they expect to be able to apply your raw intelligence to changing demands quickly. There's no point being hyper-specific about the exact software packages because that's not what they want. What they want is someone who, after talking to an interviewer for 30 minutes, leaves them with the thought "Wow, this pe…

> There's no point being hyper-specific about the exact software packages because that's not what they want

Okay. This makes it sound like they're more sophisticated but it seems more like they are less sophisticated, less specific, and a lot more vague in the job descriptions they themselves create.

If you look at any technical role, game dev or something where people are building important things at scale - there are a lot of specifics. Libraries, methodologies, where if you didn't know them you are nowhere near a fit.

I'm just wondering. It's OpenAI. Surely there is some domain-specific something beyond "has experience shipping front-end and back-end services" since that includes basically everyone.

It makes this job look like a Starbucks role.

Re: Codex Security

#126

Earlier quoted context omitted.

Professional app development requires an understanding of security.

I think the evidence contradicts you at this point

So you don't need to know anything about credit cards for someone to enter it into an app? I don't get the take (is it bad sarcasm?)

Re: Codex Security

#127

Earlier quoted context omitted.

I think the evidence contradicts you at this point

So you don't need to know anything about credit cards for someone to enter it into an app? I don't get the take (is it bad sarcasm?)

To be fair, for the vast majority of cases, no you don't.

It is extremely rare for companies to roll their own payment processing anymore, or even handle PCI scope at all.

Re: Codex Security

#128
post #127

Earlier quoted context omitted.

So you don't need to know anything about credit cards for someone to enter it into an app? I don't get the take (is it bad sarcasm?)

To be fair, for the vast majority of cases, no you don't. It is extremely rare for companies to roll their own payment processing anymore, or even handle PCI scope at all.

Credit card entry, I think you should know a few basics like don't put it in MongoDB?? Or nah? It's just like any other user data?

How about a background check - can anyone take a user-entered DL and randomly Google stuff to see what they find?

Can I store your SSN in plain text in a text file? Why not?

The user had to upload their ID for IDV but I use Vercel. I guess I have to put it on S3. What should the bucket policy be for all these driver's license photos - there are so many???

Re: Codex Security

#129

Earlier quoted context omitted.

> Have experience shipping production full-stack products across modern web frontends and backend services. I'm amazed that the requirements are so low (or at least this vague) for jobs at companies like these. Has anyone else had the experience of going to an interview and feeling like you were never asked any qualifying questions? All the questions were easy, your answers were straightforward, you "got them right",…

Not having clear, objective criteria enables arbitrary decisions (not against OP, I mean in general.. and in general I dislike this pattern a lot). On the extreme other end of the spectrum would be 100% objective criteria, and companies being forced to pick a random applicant that matches them. If they want only the best, they have to have high expectations, but be able to actually define them. You say "cultural fit"…

It’s not corruption to simply hire the people you subjectively feel a preference for working for, instead of objective criteria. It’s not public tax funds that fuel salaries, it’s your own money. You get to spend it how you like.

Yes, many jurisdictions have outlawed arbitrary discrimination against protected classes (eg race), which is an entirely different matter, and not what we are discussing here.

Re: Codex Security

#130

Earlier quoted context omitted.

If you didn't already know, jobs at highly competitive companies tend to have vague job requirements because they expect to be able to apply your raw intelligence to changing demands quickly. There's no point being hyper-specific about the exact software packages because that's not what they want. What they want is someone who, after talking to an interviewer for 30 minutes, leaves them with the thought "Wow, this pe…

> There's no point being hyper-specific about the exact software packages because that's not what they want Okay. This makes it sound like they're more sophisticated but it seems more like they are less sophisticated, less specific, and a lot more vague in the job descriptions they themselves create. If you look at any technical role, game dev or something where people are building important things at scale - there a…

I see where you're coming from, but as someone who regularly interviews engineers, I don't care about specific tech stacks when evaluating a candidate very much either. I can only think of two positions I've worked in where such a thing really mattered.

A good engineer can adapt and catch up without a lot of lead time. For a contractor, I'd be much more specific - but for someone who's going to join my team? I'm looking for a candidate that can demonstrate their problem solving ability, creative thinking and communication skills.

Other than having some kind of experience in the general domain we work in, those "soft skills" are far harder to find than specific tech experience.

Post reply on HN