security tools from AI companies feel like fire departments run by arsonists. useful, sure, but you can't help noticing who benefits from all the fires
Codex Security
211–220 of 257 posts
Re: Codex Security
#212Hey looks cool. I tried to run this on a small oss library and here's what happened: $ codex-security scan . [00:00] Preparing scan [00:00] Authentication: stored Codex credentials. [00:01] Preparing scan [00:42] Running scan [00:42] Preflight: worker delegation supported (up to 8 worker slots). [41:03] Running scan codex-security: This content was flagged for possible cybersecurity risk. If this seems wrong, try rep…
IMHO, tokens should be refunded if the agent refuses to work. Charging users for a session that produced no final output is ridiculous.
Re: Codex Security
#213Just ran it on a small repo. It ran for almost an hour and then got interrupted. It drained half my weekly usage on a Pro plan. npx codex-security scan . [00:00] Preparing scan [00:00] Authentication: stored Codex credentials. [00:03] Preparing scan [01:20] Running scan [01:20] Preflight: worker delegation supported (up to 8 worker slots). [52:47] Running scan codex-security: Could not save the Codex Security scan: R…
Oof, that's a bad outcome. Half your weekly usage and a 50-minute scan just to get a HEAD error at the end is not acceptable. --max-cost can help limit estimated spend, but that doesn't fix the underlying problem or give you your quota back. We need to handle a changing checkout and partial results much better. Sorry you ran into this. Please send me an email.
Re: Codex Security
#214Earlier quoted context omitted.
Oof, that's a bad outcome. Half your weekly usage and a 50-minute scan just to get a HEAD error at the end is not acceptable. --max-cost can help limit estimated spend, but that doesn't fix the underlying problem or give you your quota back. We need to handle a changing checkout and partial results much better. Sorry you ran into this. Please send me an email.
I set --max-cost to 100, it bailed before finishing. Unknown if I would get full results for $105 or $500. Either way I lost $100.
Re: Codex Security
#215Earlier quoted context omitted.
That’s exactly what they’re saying. With the added (and very important) detail that the people selling the fireproofing are the the same who armed everyone with flamethrowers. Why shouldn’t someone complain about that?
Idk, complain on the merits probably. If anyone can offer better fireproofing or flamethrowers, I am happy to take that solution, but until they do, I am not sure what we are talking about here.
Alternatively, let people complain about whatever is bothering them, as long as it’s done in good faith, instead of forcing them to complain only about what you think appropriate.
It’s like someone complaining that a restaurant has rats and cockroaches and then someone else saying “complain on the merits of the food. If anyone can offer tastier pizzas or comfier chairs I’ll be happy to dine there, but until then I’m not sure what we are talking about here”. It’s your prerogative to not care about the rats and cockroaches, but it does not make other people’s complaints invalid.
Re: Codex Security
#216security tools from AI companies feel like fire departments run by arsonists. useful, sure, but you can't help noticing who benefits from all the fires
If we just turn off all the computers there will be no bugs!
— Gilfoyle
Re: Codex Security
#217Alibaba just open sourced their version of a CLI code review tool too. https://github.com/alibaba/open-code-review
Re: Codex Security
#218This is going to be hell for OSS maintainers. Every llm-kiddie will be opening a security report
Re: Codex Security
#219Earlier quoted context omitted.
>> For authorized defensive work, Trusted Access for Cyber (TAC1/Daybreak) can reduce refusals Or perhaps a better option is to use something like Kimi K3 and cancel the GPT subscription altogether.
Sounds like that's the only solution. I'm so sick of this safety nonsense I was going to switch from Anthropic to OpenAI because of it. I'm so disappointed to see it's just more of the same. Model finds a vulnerability in your code but "refuses" to tell you. Words can hardly express the sheer absurdity of it.
Re: Codex Security
#220Hey HN, Michael here, co-founder of Promptfoo and one of the people working on the Codex Security CLI at OpenAI. Thanks for checking this out and for flagging the auth issues. We just open-sourced it, and there's still plenty for us to improve. Expect the product to evolve quickly. If you try it, I'd really appreciate hearing what works well and what you think we should improve. Happy to answer questions here. CLI do…
I totally missed the acquisition - but well deserved. I am currently re-evaluating PF again for my upcoming project, and happy to see that it is more than simply thriving.