5 ms·
Some irony: I subscribe to Claude and Codex (20x plans), and now Kimi. Why Kimi? because K3 is the only frontier model I can have a serious conversation with
by novaleaf 2mo ago
Some irony: I subscribe to Claude and Codex (20x plans), and now Kimi.
Why Kimi? because K3 is the only frontier model I can have a serious conversation with about my product's security.
(I did apply for OpenAi's Cyber Pilot but got no response)
- torginus 2mo agoThe product strategy of 'consumer-grade' AI making deliberately insecure software, and then selling you limited access to the model that can fix it (if they think you deserve to pay them) is just diabolical. (Grade 3 AI which can hack both previous tiers is exclusively sold to the highest bidder.)
- realusername 2mo ago> AI making deliberately insecure software, and then selling you limited access to the model that can fix it (if they think you deserve to pay them) is just diabolical. It's also not a very good marketing strategy, secure software and quality also goes in pair and it just makes me doubt about the output of Fable/Sol
- novaleaf 2mo agoI don't think it's nefarious, but the end result leads to a pretty frustrating experience by anybody needing actual security work. (and without the organizational deep pockets to obtain SOC 2 attestation)
- mathisfun123 2mo ago[flagged]
- sublinear 2mo agoThat's really delusional and dismissive of the huge amount of skill still required on the human end.
- ozgrakkurt 2mo ago> K3 is the only frontier model I can have a serious conversation with about my product's security. This is wrong IMO. You should have a serious conversation about your products security with someone who is actually trained on that subject. LLMs are useless if you don't already know more about the thing than the LLM, or if you don't care too much about the outcome (internal tools etc.)
- DrBenCarson 2mo agoExcellent, that’s what people have been doing for 40 years. Surely that means the models have 0 hope of finding successful attack vectors
- jazzyjackson 2mo agoI think I like this perspective because it points to where regulation might be more usefully applied than “the oracle must be prevented from answering certain question” and more like, “if you handle PII or provide services as a defense contractor, you may not take security advice from an oracle”
- satyrnein 2mo agoThis has been the prevailing advice all along, and yet we have security vulnerabilities everywhere that LLMs are good at spotting and exploiting. I think we need more options on the menu.
- ozgrakkurt 2mo agoYou hire someone that knows security and that guy uses an LLM. Ignorant business guy or the research engineer genius guy won’t be able to do much with just an LLM. You can easily see this if you are using LLMs in a field you are an expert in
- cyh555 2mo agoYou are right, but you can't convince anyone, because the product owner bear all the responsibilities for his/her decisions.
- xur17 2mo ago> (I did apply for OpenAi's Cyber Pilot but got no response) Same experience with Anthropic's. I applied for my employer, and.. 0 response.
- perbu 2mo agoWe got it. I can't say it has helped much, though. Fable is still completely useless for securing code. Opus does an OK job, though.
- yako21000 2mo agoHow much do both cost together? Claude Code alone is 200 bucks a month... I'm satisfied with the 100 buck subscription for now with headroom
- novaleaf 2mo agoYeah it's not cheap, it's just the normal $200 subs for each.
- rmast 2mo agoWas it applying to the program for an organization or individual? The description for the individual application page makes it sound pretty straightforward compared to getting access for an organization.
- nicce 2mo agoI think individual one still has less capabilities than the one they offer for organizations.
- novaleaf 2mo agoI applied for individuals. I did their verification steps and answered questions in a few minutes, so that was indeed easy. The problem is that was all that happened. No followup, no access, no denial. When I tried to reapply it tells me I can't apply again. OpenAi (and Anthropic) have no incentive to allow security access to individuals. I'm not a deep-pocket org or influential gov agency. Allowing individuals increases the risk of bad press (what if I do something naughty and talk about it?) so best to ignore us.
- Agingcoder 2mo agoYeah I tried to have a conversation about security yesterday with Claude and it immediately stopped me - I was taken aback, I didn’t expect it at all. This is highly problematic.
- sigmoid10 2mo agoI found GPT 5.3 was the last model that was sufficiently competent and still open to discuss security on my own github repos. 5.4 started refusing to even look at potential problems, albeit not consistently. I'm considering a Kimi subscription, but I know many employers will simply not be on board with this and I don't know if I get enough personal use out of this for the few things I run on servers. When those companies realize what they're currently missing out on, it will be a game-changer.
- gck1 2mo ago
- trollbridge 2mo agoI’m in the exact same boat, although Codex isn’t quite as bad. Fable smacked me for asking it to design a secure app without obvious security flaws and to double check it wasn’t using libraries with known security problems.
- novaleaf 2mo agoAgree, out of the two, I can get Codex to design and implement security systems (Fable just refuses to discuss). I've only used K3 a little bit, but I found that being able to discuss attack vectors and their mechanics gives me details to paste back into Codex for it to ingest. I could never have gotten there through Codex alone.
- throw10920 2mo agoI've had repeated conversations with Opus about cybersecurity and never gotten a refusal.