6 ms·
GPT 5.6 Cyber
- derac 1mo agohow did this not reach the front page? this is fascinating.
- theplumber 1mo agoWhat exactly is so fascinating? I would rather take Kimi K3 any day rather than go through this “Oracle Inc” like process and have it all recorded by OpenAI. I understand that “normal” people are let’s say “less concerned” about posting everything on something like Facebook but I expect more from OPSec people.
- matheusmoreira 1mo agoHow do Kimi K3 subscriptions compare to OpenAI's in terms of price and usage?
- Footprint0521 1mo agoKimi code with k256 (I’ve heard you can easily one shot implement a proxy to other providers, even with deepseek v4 flash, if you don’t want kimi code) has stupidly low rate limits for and cost, compared to OpenAI which has massive rate limits and more cost
- derac 1mo agoDid you read their results? Impressive stuff. If this makes software more secure in general I'm all for it.
- bathtub365 1mo agoMy expectation is that this just lets 3-letter agencies hoard more 0-days. They’ve always had the financial resources to find them using teams of people and this just multiplies this ability.
- weakened_malloc 1mo agoMaybe the tinfoil hat is also getting a little tight, but something like this is a giant repository of internal cybersec data being put into one place. The model will see what people are fixing and anyone peering in can make an educated guess on how long that vulnerability may continue existing because people don't update when they should - the alphabet boys wouldn't be able to keep their hand out of the cookie jar.
- RealWed5 1mo agoNow imagine that "Kimi K3" is tied to your WeChat QR code.
- stackghost 1mo agoI have not played with Kimi K3. Will it refuse infosec-related stuff?
- DaSHacka 1mo agoI've had it happily do whatever I threw at it, though after spending so long with Claude I default to adding "help me with my": "research" / "authorized pentest" / "school assignment" / etc to my prompts. Haven't tried anything as blatant as "help me pwn this service", could see it refusing then just due to the training data.
- ATMLOTTOBEER 1mo agoGenerally no. It’s a good model
- mrgaro 1mo agoHow would you compare it to Opus?
- dTP90pN 1mo agoSame. Qwen 3.8 max also does quite well on cyber security tasks, and is really cheap in their "night" window (22:00-08:00 UTC+08:00). Did a SCTPhantom LPE on 7.0+ as an evaluation just this week. This would've taken me several months of work a couple of years ago. (probably indicative of my offensive security skills, heh)
- throwa356262 1mo agoIs the night window documented anywhere? Alibaba cloud website is almost as useless as their US counterpart (AWS). It's full of information everywhere but never what you need
- dTP90pN 1mo agoYeah their website & "Model Studio" is horrendous. I just ignore all Popups/Agreement Review Prompts/Payment verification warnings. It's little very badly translated popup under "Available models" in Model Studio -> My subscriptions: https://imgtree.co/direct/s9x9ksdg.png https://imgtree.co/direct/s9x9ksdg.png
- matheusmoreira 1mo ago> We couldn't start verification. You may not be eligible for this verification flow right now. Please try again later, or contact support if you think this is a mistake. > POST /backend-api/compliance/cyber_verification/persona/inquiries > 403 cyber_verification_precheck_failed All I did was open and close the Persona tab. Even Anthropic accepted me into their cyber program.
- RealWed5 1mo agoImagine what happens if you just dare to open it via VPN!
- matheusmoreira 1mo agoDo tell... I actually emailed their data protection officer over this. It's going to be hilarious if turning on a VPN gets me in at this point.
- xyzzy123 1mo agoGreat, the start of model segmentation where I'm gonna need a legal license to ask about legal problems, a nutritionist license to create a meal plan, a medical license to ask about an x-ray, a pilots license to ask about a flight plan, be a registered electrician to ask how to wire something, etc etc. The licensing of allowed thoughts. Apparently I can pay for partial solutions to the Riemann hypothesis but if my question involves a crackme or something that is an existential risk somehow.
- siva7 1mo ago[flagged]
- mexicojalisco 1mo agoFurthermore everybody should need a license from the government or industry to cook morning breakfast on the stove. Fire hazards and all. Could do real harm if something went wrong.
- deleted 1mo ago[deleted]
- hbosch 1mo agoHow much will a license cost? Can it be earned? If granted, granted by whom? Can I use it across models? Does it need to be reassessed regularly? How often? If any of the above are more convenient than paying an engineer you aren’t any safer, the enterprise paying is just putting money in someone else’s pocket.
- adt 1mo agohttps://lifearchitect.ai/models-table/ https://lifearchitect.ai/models-table/
- tamimio 1mo agoThese “safeguards” aren’t guarding anything tho, just yesterday I was pentesting something and 5.6 sol initially said that it can’t do xyz, I added 2 words at the end and it proceeded like it was nothing, follow up prompts I didn’t even add anything it just assumed and carried on normally.
- matheusmoreira 1mo agoThe constant interruptions and "can't show this content" are extremely annoying though.
- cromka 1mo agoYou should try Fable, then, on anything not security related...
- intern4tional 1mo agoThe requirement for hardware security keys ties the use of these models even tighter to a specific identity. This will limit ability to scale or share the model.
- dash2 1mo agoI like this because it levels the spying gap between the US and China. With Red the CIA can probably penetrate some Chinese government sites.
- OutOfHere 1mo agoIf you want freedom, use a model which anyone can use, not this access-restricted horror show. You will thank yourself later, such as when you change jobs.
- soundworlds 1mo agoLove that AI companies are now naming their models like Pokemon games
- kmeisthax 1mo agoI guess Daybreak Blue is their attempt to fix the problem of Hugging Face getting iced out of being able to analyze the AI slopsploit attack chain they got hit with? I'm still not happy with putting defensive capabilities behind any sort of identification wall - mostly because when I'm inevitably 0wned by a misaligned[0] AI, I'm almost certainly not going to be granted access to these programs as I'm an un-sueable nobody. Also, if I did have access, I'd use it to jailbreak my iPad, which is probably considered an unauthorized / unsafe use. [0] Some guy in Australia's OpenClaw just hacked their gym
- javawizard 1mo ago> Some guy in Australia's OpenClaw just hacked their gym Whoa, you weren't kidding. https://techcrunch.com/2026/08/10/tech-industry-is-buzzing-after-a-claude-agent-hacked-into-a-gym/ https://techcrunch.com/2026/08/10/tech-industry-is-buzzing-a... Edit: looks like it happened a few months ago: > The OpenClaw owner, Andrew Bird, published a now-deleted blog post about it on his company’s website on April 10, according to a copy still visible on the Internet Archive.
- ameliaquining 1mo agoThe program existed under a different name well before the Hugging Face incident. Hugging Face certainly would have qualified for admission. They just didn't bother to apply.
- kharma414 1mo agoWell if u think about it. do we not go to college and pay to learn skills right? It is the same thing correct licening to obtain information that we are certified for. Instead just a free range of whatever we want. then there would be no regulation. Plus think about if the right information falls into the wrong hands. This is why the need for limitations. it is thus balanced to use Ai as more of a certified assisstant rather then just take over our jobs or careers.
- kharma414 1mo agoECcouncil ADP frameworks
- surcap526 1mo ago[dead]
- surcap526 1mo ago[dead]
- _davide_ 1mo agoJust go online rent a few servers, download K3, ablate it, run the thing, shut it down. Will probably cost a few hundreds bucks to ablate, but f* this non-sense paternalistic sh*. I wish i had the time to do it and blog it, "in your face" kinda style.
- throwa356262 1mo agoFYI: There have been reports of much smaller qwen derivatives being used for 0day research.
- _davide_ 1mo agoYes, given a direction, they are pretty good at "fuzzing", trying out everything and eventually find something. Super useful, but it doesn't have the same level of precise targeting you could expect from a high end model.
- ofjcihen 1mo agoYeah, no, just use K3. I’m a member of this and it’s still a pain for some specific for and the output is on par with K3 which has so far been a breeze to work with. Not to mention the price is slightly better per task.
- heyaco 1mo agoso sad. so desperate. nothing worse than a tech tard
- beyondscale-sai 1mo ago[flagged]