Live data from Hacker News

Codex Security

github.com

201–210 of 257 posts

Re: Codex Security

#201
post #144

Earlier quoted context omitted.

Where did you get that from? That‘s not what the license says: https://huggingface.co/moonshotai/Kimi-K3/blob/main/LICENSE The current price is likely a result of the high demand and the high requirements of this model.

if you’re hosting it then you have to have an agreement with Moonshot, which presumably includes terms about pricing.

Only if "the aggregate revenue of the Licensee and its affiliates exceeds 20 million US dollars (or the equivalent in other currencies) in total over any consecutive 12 months"

Re: Codex Security

#202
I've heard great reviews about this

"If we had only used this tool, OpenAI would've had to pay off another patsy for their marketing stunt" -- Huggingface

"The 'S' in OpenAI is for "Security". Ever since we developed this tool we've had almost zero AI generated reports of outbreaks of allegedly-rogue AI agents breaking out of allegedly-secure testing environments, probably" -- OpenAI

Re: Codex Security

#203
post #3

I seem to have gotten a bunch of you are trying to stuff we don't allow errors.. very annoying. Can they explain what types of projects it works on and how does it check I own it? Like will it just not work on Linux kernel even on my own patches to it?

Fair question, and I agree the refusals are frustrating. The CLI doesn't do a repository-ownership check. Public projects are supported, and reviewing your own Linux kernel patches is the kind of defensive work we want to support. The refusals come from model guardrails, which can be overly cautious. Trusted Access for Cyber (TAC1/Daybreak) is a separate, approved access path that can reduce those refusals. If you're…

I don't think I should share it publicly since it was a proprietary piece of code but is there a way to not have it waste so many tokens if it fails this feels very very maddening seeing your tokens burn but get zilch for it in return maybe I and my company(in API costs it burnt over 100+$ of tokens a good chunk of my weekly limit for nothing) are too poor for it...

Getting into the Cyber program seems like a hassle as a freelance/open source person with tiny projects. Think used in production at 2-3 companies but only 20 something stars(ofc I don't market it but it just feels very unfair).

Re: Codex Security

#204
post #145

Hey looks cool. I tried to run this on a small oss library and here's what happened: $ codex-security scan . [00:00] Preparing scan [00:00] Authentication: stored Codex credentials. [00:01] Preparing scan [00:42] Running scan [00:42] Preflight: worker delegation supported (up to 8 worker slots). [41:03] Running scan codex-security: This content was flagged for possible cybersecurity risk. If this seems wrong, try rep…

Same happened to me. Very disappointing, this should be mentioned before the user even authenticates in the onboarding phase of the product asking the user if they have acquired the whitelisting from OpenAI and want to proceed or not! But running for 35+ minutes plus to give such a response is very disappointing and very awkward! Not to mention the lost weekly tokens!

Re: Codex Security

#205
post #145

Hey looks cool. I tried to run this on a small oss library and here's what happened: $ codex-security scan . [00:00] Preparing scan [00:00] Authentication: stored Codex credentials. [00:01] Preparing scan [00:42] Running scan [00:42] Preflight: worker delegation supported (up to 8 worker slots). [41:03] Running scan codex-security: This content was flagged for possible cybersecurity risk. If this seems wrong, try rep…

I was going to switch to OpenAI and away from Anthropic because of "safety" nonsense like this. Really disappointed to discover it's just gonna be more of the same. Looks like Chinese models are the only ones without any of this safety bullshit.

I've switched to Kimi personally and it has way less guard nonsense like this.

Re: Codex Security

#206
post #197

Earlier quoted context omitted.

comment feels like someone complaining about being offered a fireproofing solution in the age of flamethrowers.

That’s exactly what they’re saying. With the added (and very important) detail that the people selling the fireproofing are the the same who armed everyone with flamethrowers. Why shouldn’t someone complain about that?

Idk, complain on the merits probably. If anyone can offer better fireproofing or flamethrowers, I am happy to take that solution, but until they do, I am not sure what we are talking about here.

Re: Codex Security

#208

Earlier quoted context omitted.

> now that humans write less than 99% of code, the most important criteria for a language isn't readability please tell me you're reading the AI code

Have it run fuzz and test suites. Get with it man. Most of my LLM projects have massive test suites that do a far better job then I ever would have.

Did you look at those test suites? Sometimes they test nothing.

Re: Codex Security

#210
post #145

Hey looks cool. I tried to run this on a small oss library and here's what happened: $ codex-security scan . [00:00] Preparing scan [00:00] Authentication: stored Codex credentials. [00:01] Preparing scan [00:42] Running scan [00:42] Preflight: worker delegation supported (up to 8 worker slots). [41:03] Running scan codex-security: This content was flagged for possible cybersecurity risk. If this seems wrong, try rep…

I was going to switch to OpenAI and away from Anthropic because of "safety" nonsense like this. Really disappointed to discover it's just gonna be more of the same. Looks like Chinese models are the only ones without any of this safety bullshit.

you should give openai a try. ive been really happy with them these last few weeks
Post reply on HN