xyzzy123 6 days ago

Great, the start of model segmentation where I'm gonna need a legal license to ask about legal problems, a nutritionist license to create a meal plan, a medical license to ask about an x-ray, a pilots license to ask about a flight plan, be a registered electrician to ask how to wire something, etc etc. The licensing of allowed thoughts.

Apparently I can pay for partial solutions to the Riemann hypothesis but if my question involves a crackme or something that is an existential risk somehow.

  • RealWed5 6 days ago

    +1. And these ^^^ are exactly my thoughts for which I had been downvoted to oblivion before. TaDa. They materialise.

    • RealWed5 5 days ago

      LOL ... and same people keep downvoting me. Right. Good luck.

  • stackghost 6 days ago

    Just today, 5.6-sol refused to elaborate on a security vulnerability it claimed it had identified in my code. It could plainly see the git history with my name on every commit going back to inception, but apparently elaborating on the nature of a purported vulnerability is too scary for openai.

    It would fix it for me, automatically, if I was willing to let it run amok in my codebase. But asking if the "vuln" was exploitable triggered the guardrails and a "we can't show you this content" error because I am not part of the cybersecurty Trusted Access bullshit.

    • ch4s3 6 days ago

      Could you ask it to write a failing test before fixing it?

      • stackghost 6 days ago

        I could also ask it to fix it and look at the diff, but that's rather beside the point, don't you think?

        • ch4s3 5 days ago

          Oh totally, it’s pretty silly.

    • graceful6800 6 days ago

      I had 5.6 refuse to back up my android tablet the other day because it involved root access.

      Outstanding technology, truly amazing what man has managed to create.

      • DoctorOetker 6 days ago

        I have heard AI can already fly (it carries your laptop to the ceiling when it does), but usually it refuses to demonstrate this capability for safety reasons.

        • anakaine 5 days ago

          I've heard it can ramp the fans up so hard it'll suck the gold right off your motherboard traces and send it to OpenAI. This is the thing that the US administration is worried about, because Chinese open weights models will copy the function and then send all that gold to China, and the US will have to dip into the stores at Fort Knox, and potentially devalue the greenback.

  • bryanlarsen 6 days ago

    It's the open weight models that will save us from this fate.

    OTOH, this is the cudgel that incumbents will use to get the government to protect them from open weight models.

    • ragequittah 5 days ago

      I imagine the cudgel will be when the models are good enough and some moron sets their openclaw to hack a hospital or other critical infrastructure. I feel like we've learned nothing from the ransomware problems of recent history. Are we really saying it's a good idea to throw such capabilities in every emo teenager's hands because freedom?

  • pants2 5 days ago

    The frontier labs would rather charge a premium for the best capabilities. You joke but they will probably soon have a GPT-bio that they license to Pfizer and a GPT-quant that they license to Citadel, rather than keeping those valuable capabilities in the public models.

    • subhobroto 5 days ago

      > but they will probably soon have a GPT-bio that they license to Pfizer and a GPT-quant that they license to Citadel, rather than keeping those valuable capabilities in the public models

      Nein. Neither Pfizer nor Citadel are going to use a hosted model - their whole business is IP. They will invest in self hosting models. Self hosting is becoming a big deal in the industries you're talking about.

      Why?

      Neither Pfizer nor Citadel wants to pay a supplier/vendor to build a core capability that the supplier/vendor will turn around and sell to their competition.

      • foobar10000 5 days ago

        Citadel already is. They are happy to do it - bedrock is the host of choice. They are less happy about cost - but that is a question of value :)

        • subhobroto 5 days ago

          Citadel are using which models on bedrock and for what purpose?

          Core portfolio research? Update Confluence pages and JIRA tickets? Create marketing copy?

      • pants2 5 days ago

        Sure, and OpenAI will be happy to let them self-host for a large fee. However I doubt that Pfizer will be developing their own frontier models for biological research.

_davide_ 5 days ago

Just go online rent a few servers, download K3, ablate it, run the thing, shut it down. Will probably cost a few hundreds bucks to ablate, but f* this non-sense paternalistic sh*.

I wish i had the time to do it and blog it, "in your face" kinda style.

  • throwa356262 5 days ago

    FYI:

    There have been reports of much smaller qwen derivatives being used for 0day research.

    • _davide_ 5 days ago

      Yes, given a direction, they are pretty good at "fuzzing", trying out everything and eventually find something. Super useful, but it doesn't have the same level of precise targeting you could expect from a high end model.

tamimio 6 days ago

These “safeguards” aren’t guarding anything tho, just yesterday I was pentesting something and 5.6 sol initially said that it can’t do xyz, I added 2 words at the end and it proceeded like it was nothing, follow up prompts I didn’t even add anything it just assumed and carried on normally.

  • matheusmoreira 6 days ago

    The constant interruptions and "can't show this content" are extremely annoying though.

    • cromka 4 days ago

      You should try Fable, then, on anything not security related...

kmeisthax 6 days ago

I guess Daybreak Blue is their attempt to fix the problem of Hugging Face getting iced out of being able to analyze the AI slopsploit attack chain they got hit with? I'm still not happy with putting defensive capabilities behind any sort of identification wall - mostly because when I'm inevitably 0wned by a misaligned[0] AI, I'm almost certainly not going to be granted access to these programs as I'm an un-sueable nobody.

Also, if I did have access, I'd use it to jailbreak my iPad, which is probably considered an unauthorized / unsafe use.

[0] Some guy in Australia's OpenClaw just hacked their gym

  • javawizard 6 days ago

    > Some guy in Australia's OpenClaw just hacked their gym

    Whoa, you weren't kidding.

    https://techcrunch.com/2026/08/10/tech-industry-is-buzzing-a...

    Edit: looks like it happened a few months ago:

    > The OpenClaw owner, Andrew Bird, published a now-deleted blog post about it on his company’s website on April 10, according to a copy still visible on the Internet Archive.

  • ameliaquining 4 days ago

    The program existed under a different name well before the Hugging Face incident. Hugging Face certainly would have qualified for admission. They just didn't bother to apply.

kharma414 6 days ago

Well if u think about it. do we not go to college and pay to learn skills right? It is the same thing correct licening to obtain information that we are certified for. Instead just a free range of whatever we want. then there would be no regulation. Plus think about if the right information falls into the wrong hands. This is why the need for limitations. it is thus balanced to use Ai as more of a certified assisstant rather then just take over our jobs or careers.

intern4tional 6 days ago

The requirement for hardware security keys ties the use of these models even tighter to a specific identity.

This will limit ability to scale or share the model.

OutOfHere 6 days ago

If you want freedom, use a model which anyone can use, not this access-restricted horror show. You will thank yourself later, such as when you change jobs.

ofjcihen 5 days ago

Yeah, no, just use K3. I’m a member of this and it’s still a pain for some specific for and the output is on par with K3 which has so far been a breeze to work with.

Not to mention the price is slightly better per task.

dash2 6 days ago

I like this because it levels the spying gap between the US and China. With Red the CIA can probably penetrate some Chinese government sites.

heyaco 5 days ago

so sad. so desperate. nothing worse than a tech tard

kharma414 6 days ago

ECcouncil ADP frameworks

soundworlds 6 days ago

Love that AI companies are now naming their models like Pokemon games

derac 6 days ago

how did this not reach the front page? this is fascinating.

  • theplumber 6 days ago

    What exactly is so fascinating? I would rather take Kimi K3 any day rather than go through this “Oracle Inc” like process and have it all recorded by OpenAI.

    I understand that “normal” people are let’s say “less concerned” about posting everything on something like Facebook but I expect more from OPSec people.

    • matheusmoreira 6 days ago

      How do Kimi K3 subscriptions compare to OpenAI's in terms of price and usage?

      • Footprint0521 6 days ago

        Kimi code with k256 (I’ve heard you can easily one shot implement a proxy to other providers, even with deepseek v4 flash, if you don’t want kimi code) has stupidly low rate limits for and cost, compared to OpenAI which has massive rate limits and more cost

    • derac 6 days ago

      Did you read their results? Impressive stuff. If this makes software more secure in general I'm all for it.

      • bathtub365 6 days ago

        My expectation is that this just lets 3-letter agencies hoard more 0-days. They’ve always had the financial resources to find them using teams of people and this just multiplies this ability.

        • weakened_malloc 6 days ago

          Maybe the tinfoil hat is also getting a little tight, but something like this is a giant repository of internal cybersec data being put into one place. The model will see what people are fixing and anyone peering in can make an educated guess on how long that vulnerability may continue existing because people don't update when they should - the alphabet boys wouldn't be able to keep their hand out of the cookie jar.

    • RealWed5 6 days ago

      Now imagine that "Kimi K3" is tied to your WeChat QR code.

    • stackghost 6 days ago

      I have not played with Kimi K3. Will it refuse infosec-related stuff?

      • DaSHacka 5 days ago

        I've had it happily do whatever I threw at it, though after spending so long with Claude I default to adding "help me with my": "research" / "authorized pentest" / "school assignment" / etc to my prompts. Haven't tried anything as blatant as "help me pwn this service", could see it refusing then just due to the training data.

      • ATMLOTTOBEER 5 days ago

        Generally no. It’s a good model

        • mrgaro 5 days ago

          How would you compare it to Opus?

    • dTP90pN 5 days ago

      Same. Qwen 3.8 max also does quite well on cyber security tasks, and is really cheap in their "night" window (22:00-08:00 UTC+08:00). Did a SCTPhantom LPE on 7.0+ as an evaluation just this week. This would've taken me several months of work a couple of years ago. (probably indicative of my offensive security skills, heh)

      • throwa356262 5 days ago

        Is the night window documented anywhere?

        Alibaba cloud website is almost as useless as their US counterpart (AWS). It's full of information everywhere but never what you need

        • dTP90pN 5 days ago

          Yeah their website & "Model Studio" is horrendous. I just ignore all Popups/Agreement Review Prompts/Payment verification warnings.

          It's little very badly translated popup under "Available models" in Model Studio -> My subscriptions: https://imgtree.co/direct/s9x9ksdg.png

matheusmoreira 6 days ago

> We couldn't start verification. You may not be eligible for this verification flow right now. Please try again later, or contact support if you think this is a mistake.

> POST /backend-api/compliance/cyber_verification/persona/inquiries

> 403 cyber_verification_precheck_failed

All I did was open and close the Persona tab.

Even Anthropic accepted me into their cyber program.

  • RealWed5 6 days ago

    Imagine what happens if you just dare to open it via VPN!

    • matheusmoreira 6 days ago

      Do tell... I actually emailed their data protection officer over this. It's going to be hilarious if turning on a VPN gets me in at this point.