Live data from Hacker News

Trusted access for the next era of cyber defense

openai.com

41–50 of 79 posts

Re: Trusted access for the next era of cyber defense

#41
post #21

Earlier quoted context omitted.

That’s the whole point of this variant of the model, it won’t have those guardrails.

Yes. But "perform a humiliation ritual of KYC to access the actual model instead of the nerfed version of it that's so neurotic about cybersec you have to sink 400 tokens into getting it to a usable baseline" does not inspire any confidence at all.

It seems reasonable for a company to require KYC for a product that's dual use – especially a novel one that's built for security research.

Privacy concerns aside, the KYC process for OpenAI was self-serve and took about a minute.

Re: Trusted access for the next era of cyber defense

#42

I completed the "Trusted Access" verification, but it seems to have unlocked nothing in the OpenAI API or Codex models. Just FYI for others.

I see a Security button in the what’s new box in the Codex section of the ChatGPT website. It appears to allow me to run vulnerability scans against my connected GitHub repositories. Direct link: https://chatgpt.com/codex/cloud/security

That’s been there for awhile.

Re: Trusted access for the next era of cyber defense

#43

I don't think they've added enough cyber. My cyber workflow demands more trusted access for cyber so that I can use these cyber-permissive models for my cybersecurity.

It's a source of minor, but persistent, annoyance that security people have tried to abscond with the prefix cyber, morphing it into a synonym for security.

Having grown up reading cyberpunk novels about life in cyberspace, a passing interest in cybernetics (though not of the Sirius Cybernetics Corporation variety), it's frustrating to lose a 'this means computer or internet related' prefix.

Re: Trusted access for the next era of cyber defense

#44
post #43

I don't think they've added enough cyber. My cyber workflow demands more trusted access for cyber so that I can use these cyber-permissive models for my cybersecurity.

It's a source of minor, but persistent, annoyance that security people have tried to abscond with the prefix cyber, morphing it into a synonym for security. Having grown up reading cyberpunk novels about life in cyberspace, a passing interest in cybernetics (though not of the Sirius Cybernetics Corporation variety), it's frustrating to lose a 'this means computer or internet related' prefix.

Hmm, I guess this puts the unregulated banking enthusiasts’ stealing of the crypto prefix in a new light.

Re: Trusted access for the next era of cyber defense

#45

I don't think they've added enough cyber. My cyber workflow demands more trusted access for cyber so that I can use these cyber-permissive models for my cybersecurity.

Whoa hey now, if they just give out all the cyber all at once they might run out or worse, the bad guys will horde all the cyber for themselves! No no, best to have them distribute the cyber to us responsibly.

Just wait until you meet the Cybermen.

Re: Trusted access for the next era of cyber defense

#46
post #7

This approach means only a tiny portion of the population will every qualify. Doesn't that make everyone else beholden to those few, who are beholden to OpenAI? Another solution is to make software makers responsible and liable for the output of their products. It's long been a problem that there is little legal responsibility, but we shouldn't just accept it. If Ford makes exploding cars, they are liable. If OpenAI…

> Another solution is to make software makers responsible and liable for the output of their products. It's long been a problem that there is little legal responsibility, but we shouldn't just accept it. If Ford makes exploding cars, they are liable. If OpenAI makes software that endangers people, it should be the same. That kind of thinking is exactly why LLMs are so censored, because people think OAI should be liab…

"It's just a neutral tool" gets a lot harder to claim once a vendor starts specifically training and marketing the model for its ability to bypass security controls.

Yes, pentesting tools, even automated ones, are often legal. But they commonly do run up against legal restrictions and risks. They're marketed very differently from ChatGPT.

Re: Trusted access for the next era of cyber defense

#48

I completed the "Trusted Access" verification, but it seems to have unlocked nothing in the OpenAI API or Codex models. Just FYI for others.

So it seems like you just…have it once you get approved. I’m testing it now and nothing indicates I’m running a different model but it just doesn’t fight me on cybersecurity stuff
Post reply on HN