10 ms·
OpenAI DayBreak – GPT-5.5-Cyber
- ramon156 3mo agoAI companies yearn for otgs built on AI tools
- lionkor 3mo agoThis is how you do it when you're not AS childish. You go "here's a model for cybersecurity" and put a price on it. I know they're releasing it to some vendors first, etc. but the lack of a clown spectacle is nice. The whole "it's too dangerous to release!" is complete hogwash. A person can take a hammer, walk out in the street, and we can count how many people he can kill with the hammer before he is stopped. My local hardware store still sells hammers, and I haven't seen the CEO of it claim that their hammers are much more dangerous and it's totally going to end the world if you allow any random person to have one!
- raincole 3mo agoIt's amusing that what Anthropic does is basically: 1. Browse the internet 2. See what people hate about OpenAI 3. Adopt the worse version of it 4. Profit? Sam Altman fearmongered about AI alignment - we fearmonger harder. OpenAI is CloseAI now - we are even less open. OpenAI is going to IPO - we IPO first.
- ralphington 3mo agoI don't have a horse in the race, but these comments are remarkably toxic. This reminds me of the RTFM epidemic on early Stack overflow.
- bob1029 3mo agoThe risk of catching federal charges, proper jail time and aggressive responses from law enforcement is a far more effective means of preventing malicious behavior than anything proposed so far. I can go into stores that sell things that are much more dangerous than hammers (or frontier cyber models) and no one will give me a hard time about it.
- ragequittah 3mo agoIf that hammer could allow people to go into people's homes / work en masse, steal all their information, blackmail them, steal their identities, break their systems (including those of hospitals and other critical infrastructure) and generally help fund bad actors through it all we'd think of having restrictions on hammers too. A hammer can't screw people over by the millions. I don't like this argument specifically with AI. Facial recognition everywhere you go is just a tool. Your job creating a detailed profile on exactly how you work, who you talk to, and about what is just a tool. The tools have become so good and easy to use we have to have serious discussions about them before things get out of hand.
- OutOfHere 3mo agoDid you see how close the non-sheltered available models come? They come quite close. Most people aren't even using them for this purpose, but they could, and this is our reality. This is why your argument fails.
- ben_w 3mo agoDisagree. @lionkor compared them to a hammer, and @ragequittah is saying they're not like a hammer. The narrow gap between downloadable and frontier models is tangential to this. If you want to expand on the "hammer" metaphor, the downloadable models are a small construction/demolitions firm, and the frontier models are a big construction/demolitions firm. In this analogy, there's no training school or certifications for the staff either of them hire, and society is still working out what public liability requirements and planning permission laws are even though both companies are being hired all over the place, because everything they do was only invented a few years ago.
- estearum 3mo agoDoes your local store sell aerosolized anthrax?
- deleted 3mo ago[deleted]
- deleted 3mo ago[deleted]
- throwaway888abc 3mo agoCan someone on HN with access to it fix the Fable / Mythos so it's secure to use again and therefore available ?
- joe_the_user 3mo ago[dead]
- brcmthrowaway 3mo agoGamechanger
- daflip 3mo agoI guess eventually the whole process can be completely autonomous, what could possibly go wrong :-)
- arikrahman 3mo agoIt's good looking forward to wrapping it around Reasonix
- taspeotis 3mo agoI don't know what the solution to this is, but I find it somewhat unfair that I pay money to Anthropic, and I pay money to OpenAI, and neither of them will let me use their best models for securing the software I work on. Admittedly Opus 4.8 xhigh does a good job, but are my customers not entitled to have more security from a Fable/Mythos or GPT-5.5-Cyber audit over the codebase? Or I guess the inverse question: why aren't they allowed that audit? (Fable/Mythos being unavailable notwithstanding.) It seems OpenAI will at least let me do this narrowly, at greater cost, by using one of their partners. But I already pay them money!
- MrOrelliOReilly 3mo agoI'm not sure I follow your logic. Paying for a service does not mean you get access to all potential services a provider offers. Providers can choose to keep some services internal. Silly example: I pay Netflix for their most basic plan, so I get ads. Just because I already pay them money, doesn't mean I have a right to no ads! It also doesn't mean I have a right to 8k streaming; maybe Netflix reserves that for their internal cinema.
- Intermernet 3mo agoWhen Netflix launched, you got the service without ads. That has changed. That's what's known as a rug-pull.
- NichoPaolucci 3mo agoBoth companies offer "MAX" or "PRO" plans - and the best models were available to those customers. This new wave of "It's too dangerous for the public" is a new initiative from both companies. I agree with your overall sentiment. Paying for "Claude Mini" doesn't get you "Claude Maximos". However, the overall precedent that the companies have set is that if you pay for the top tier subscription, you get the top tier model. That's not true any more.
- estearum 3mo agoJust like when you buy a top of the line camera or car, and then they release a new one, you are entitled to the now-top-of-the-line camera or car. What the heck come on.
- tetrisgm 3mo agoIt's a pretty interesting opportunity. I wonder if they will reach to companies and tell them how many things they could fix and how many are critical, before selling them the solution.
- KeplerBoy 3mo agoIf they won't, some consultant with a subscription eventually will.
- spwa4 3mo agoDoes the EU CRA now mean that every European company that either sells software or sells anything that has a software component is now forced to pay for this by September and update their software?
- mentalgear 3mo agoNo one commenting on the fact that oAI is releasing a Claude Mythos-class model - with apparent 0 restrictions or concerns by the US government, while Anthropic's (their competitor) model has been pulled weeks prior by the administration for 'security' reasons. It certainly has nothing to do with openAI's co-founders donating to the current administrations election fund, are actively supporting the DoW war efforts of autonomous weapons and also otherwise being ideology tightly coupled with the current US government.
- flanked-evergl 3mo agoDo you think that Anthropic's models would have been pulled if they did not say for months how their models is basically going to break the whole internet and that governments should most definitely restrict AI? I doubt it. The problem is, though, given Anthropic have said all of that, they really have very little grounds for objecting to the US government's intervention here. Everything that the government would have to prove to justify their intervention has already been freely admitted by Anthropic, even though the "admission" was maybe more intended as a marketing ploy.
- netdur 3mo agoWhy do you want to tax openai on anthropic's fud mistake?
- postalcoder 3mo agoMan, some of you will invent conspiracy theories to justify some deeply cynical fiction. OAI has been more proactive about doing customer KYC than A\. OpenAI, four months ago, started to require users to verify their identity if they flagged their activities on frontier models (gpt-5.3-codex and higher) as risky. Their filters were originally quite coarse and it resulted in a ton of normal tasks being flagged. There was a lot of drama about it at the time, but it seems like things have smoothed out. KYC goes back to a year or two ago. API access to gpt-image-1 required it. https://openai.com/index/trusted-access-for-cyber/ https://openai.com/index/trusted-access-for-cyber/
- blahblaher 3mo ago
- theplumber 3mo agoOk so why I don’t have access to this if I already pay for the max plan? Should I pay a security researcher to run codex on my code? Is this how it is supposed to work? Let’s hope we get some real cyber models that people can actually use from the Chinese without the stupid application forms.
- deleted 3mo ago[deleted]
- baq 3mo agoWhy do you think you should have access…? People who pay enterprise API rates also don’t if this makes you feel better (it shouldn’t, you shouldn’t have felt bad in the first place)
- civet_java 3mo agoI'm not sure I understand what you're arguing for? There are massive companies that collectively profiting off of stolen IP and are now gatekeeping even their paid offerings - surely consumers will rail against this? Personally, I feel very bad and can't wait for Chinese models to continue improving as much as they can prior OpenAI's and Anthropic's IPOs.
- baq 3mo agoI’m not arguing for anything, actually. The ‘fair’ ship has sailed, even if the pirates somehow get shut down (which would be suicide by USG, won’t happen, national security issue), open Chinese models are not even hiding the fact that they distill from the frontier US labs, thus benefiting indirectly from the stolen content. Note I don’t particularly like the ‘stolen’ word here as I don’t like when the music and film companies use it in the same context. Copyright infringement? Sure. Theft? No.
- civet_java 3mo ago> I don’t particularly like the ‘stolen’ word here Except that's the standard that we've measured everyone with up until the LLM/generative tech boom. I don't see why the benchmarks should change now. I realise my argument doesn't move reality but that doesn't mean we shouldn't call a spade a spade. Said companies carried out theft (or copyright infringement if you prefer) at industrial scale which is far more reprehensible crime against humanity than anything the individuals we think of as "digital pirates" have committed. > open Chinese models are not even hiding the fact that they distill from the frontier US labs The difference is they return to the same system that they feed from (indirectly); people get access to model weights even if the entire model isn't open source. The same can't be said for OpenAI, Anthropic, Google etc (who also benefit from Chinese models and train on them). Sure, the alternatives aren't a panacea of fairness but I'd much rather advocate for and support the thieves who give me a better deal if my choice is limited to thieves. Especially if thieves aren't hostile to their customers like Anthropic is (which is why I replied to you in the first place).
- elashri 3mo agoI think if nothing happens from the government, then this would be a very good example of the benefit of keeping your mouse shut especially if you are lying to get some hype like Anthropic did for months.
- GL26 3mo agoWould love to see the benchmark comparison between Mythos / Fable and GPT-5.5-Cyber
- mijoharas 3mo agoDo you mean full benchmarks? Because from the article they claim 85.6 for 5.5-Cyber vs. 83.8 for mythos on Cybergym.
- sigbeta 3mo agowhats the point of a benchmark if its not deployable? another glasswing pr stunt to me
- baq 3mo agoDefinitely a PR stunt that I had to reboot my boxen every other day in May for security patches
- lisa_luoyf 3mo agoInteresting release. I’m most curious about how well this holds up in messy real-world environments, since that’s usually where specialized benchmark gains get tested.
- Recursing 3mo agoI see a lot of knee-jerk comments to this, but I highly recommend running a scan ( https://openai.com/daybreak/codex-security-plugin/#codex-cli https://openai.com/daybreak/codex-security-plugin/#codex-cli ) in your projects so you can evaluate it yourself. It found a real security issue in a project of mine, with very few false-positives. Its built-in resume mechanism didn't work after it crashed when running out of my 5 hour session limit, but Claude Code was easily able to resume it 5 hours later reading the session logs and https://openai.com/codex/security/scan.sh https://openai.com/codex/security/scan.sh
- deleted 3mo ago[deleted]
- egorfine 3mo agoI read this news as white noise because there is no scenario in which I will be allowed access to this model. First, I happen to be a citizen of a country that is not the USA. What's more shocking is that I'm not even located in the US. Thus in the eyes of OpenAI I do not exist in regard to SOTA security models. Second, I will never ever do KYC with a company that provides text transformation services*. Third, even if I did, I will not be able to pass KYC because the typical KYC requirements are strictly tailored to a certain subset of the world's population and lifestyle choices, tuned by Americans according to their world view. Fourth, even if I pass KYC, my account will be banned by OpenAI immediately on the first prompt because they have close to 1B users and couldn't care less about any single one of them. (*) which are nothing short of amazing and are changing the world, there's no doubt about that.
- bilekas 3mo agoThere is so much to unpack here. > Thus in the eyes of OpenAI I do not exist in regard to SOTA security models. I'm not seeing anywhere it says it's only limited to the U.S. Only that they had 'ongoing dialogue' with them. Which reads weird to me, how can an ongoing dialogue be past tense? But I digress. > We’ve had ongoing dialogue with the U.S. government about our cyber approach, including today’s announcements and on our preparation for upcoming model releases. > Third, even if I did, I will not be able to pass KYC because the typical KYC requirements are strictly tailored to a certain subset of the world's population and lifestyle choices, tuned by Americans according to their world view. KYC is just that, Know Your Customer, if your 'permitted customers' are security researchers in the industry with a proven identity of employment etc then that is the KYC process, I don't see any issues with that. > even if I pass KYC, my account will be banned by OpenAI immediately on the first prompt because they have close to 1B users and couldn't care less about any single one of them Why do you assume this? Are you planning on intentionally trying to do something actively nefarious ? It's such a strange take.
- egorfine 3mo ago> how can an ongoing dialogue be past tense? Easy: it can be considered past tense in case "ongoing dialogue" is a corporatespeak for "f..k you". Which I believe is the case here. But that's an opinion. > Know Your Customer [..] I don't see any issues with that This might be the case if you're coming from a standpoint I have mentioned: the American one. This is a world view where everybody have physical paper documents proving residence, every labour effort is arranged in a very specific legal framework, every person have an address in a specific format, every person has one of just a few types of ID documents, etc, etc. Problem is, the world have vast, vast differences in all of the mentioned areas and KYC companies couldn't care less because they are a business and they make money by KYCing as much people as possible for as little spend as possible. Thus they simply ignore any case that's not mainstream no matter how perfectly legal it is. Being a digital nomad I cannot pass KYC at the vast majority of online services. My passport is under no sanctions, I do have residency in the first world country, etc., but passing KYC at Persona and others is not possible. >> my account will be banned by OpenAI immediately > Why do you assume this? Because of the risk profile. The company has no way of knowing whether "find all security vulnerabilities in this code" is a request from a whitehat or a blackhat hacker. The risk of someone using GPT to hack yet another DeFi project for a hundred millions while mentioning OpenAI is higher than perhaps a million user accounts, let alone a single one.
- KronisLV 3mo agoSince this is more powerful than Fable in some of the benchmarks, surely it'll also get export controls... right? Right?
- beyondscaletech 3mo ago[flagged]
- theodorespeak 3mo agoLet's see if I can connect the dots as well as I think I can. Just putting it here for posterity. Like those movies before them, The Creator will be a cult classic in a few years. The acting was okay, the story was okay.The vfx were great. The premise is prophetic. America and China will go to war over AI. America will try and contain it for themselves. China will keep on trying to keep it accessible. After endless negotiations between the two superpowers, there is no more room left for talking. The free (not as in beer) AI models were always seemingly slightly worse than the proprietary American models. A barely noticeable difference on most tasks, but a difference nonetheless. The breakthrough came when people, companies and governments began chaining and pooling models and infrastructure together,because they were free to do so, thereby creating behemoths that America could not outclass, outsmart or outspend. And when you stake your whole future on that one thing, it's winner take all. So for that reason they all had had to die. And so the war began...
- nova22033 3mo agoChinese and Russian intel agencies can set up American shell corporations and buy all of our personal data....but using a model to secure my customer? Well...no...you can't have that.
- kstkrv 3mo agoIs it only my feeling, that the US government rolled back the Fable release, because they wanted their guy to get to the market before Anthropic?
- bwfan123 3mo agoSecurity is a great business model. You sell locks, and if thieves break in, you sell more and stronger locks. There are no consequences for the lock-maker. Similarly, AI tools can both find and fix vulnerabilities. Not only that, AI can create vulnerabilities in the code it generates. Now that is a perpetual money machine.
- Oarch 3mo agoRealistically, what can these types of commitments look like for the AI frontier companies, moving forward? They're releasing ever more powerful models with stronger offensive capabilities. So do they have to help bolster the defense of all existing software, just... forever? If we advance both the offence and defense with each new release, is this sustainable?
- jasonvorhe 3mo ago"trusted defenders" sounds really Orwellian. Reminds me of EU's "trusted flaggers": https://digital-strategy.ec.europa.eu/en/policies/trusted-flaggers-under-dsa https://digital-strategy.ec.europa.eu/en/policies/trusted-fl... I don't trust any of these people. Meanwhile I'm paying ChatGPT and Claude and can't use their top-tier levels because they assume I'm some security risk/terrorist. Local AI is our only hope.
- dofm 3mo agoWhy not stop paying for ChatGPT and Claude, then? Like, seriously, while you can, invest in your own stack or find cloud alternatives. If you actually want to use these products, the easiest way you will contribute to changing their money-grubbing minds about their policies and offerings, is to stop giving them yours. Peace of mind and control of your destiny is worth a bit of cash. And there's seemingly little risk of any kit you buy radically depreciating in cost. I am still really cynical about all of this BS but I must say I am fully impressed by the diligence and quality of some of the open source tooling — Unsloth Studio, Opencode, Paseo, Pi, etc. And I look at it and think: putting aside local models (and I am not sure you should, even now), is this stuff really so inferior that it's worth risking a critical dependency on a commercial cloud product that might get switched off with no notice?
- _rwo 3mo agoran the security 'plugin' on small app, in 15 min it eat up all of my quota - so it did exactly what I was expecting it to do