Great, the start of model segmentation where I'm gonna need a legal license to ask about legal problems, a nutritionist license to create a meal plan, a medical license to ask about an x-ray, a pilots license to ask about a flight plan, be a registered electrician to ask how to wire something, etc etc. The licensing of allowed thoughts.
Apparently I can pay for partial solutions to the Riemann hypothesis but if my question involves a crackme or something that is an existential risk somehow.
Just today, 5.6-sol refused to elaborate on a security vulnerability it claimed it had identified in my code. It could plainly see the git history with my name on every commit going back to inception, but apparently elaborating on the nature of a purported vulnerability is too scary for openai.
It would fix it for me, automatically, if I was willing to let it run amok in my codebase. But asking if the "vuln" was exploitable triggered the guardrails and a "we can't show you this content" error because I am not part of the cybersecurty Trusted Access bullshit.
I have heard AI can already fly (it carries your laptop to the ceiling when it does), but usually it refuses to demonstrate this capability for safety reasons.
I've heard it can ramp the fans up so hard it'll suck the gold right off your motherboard traces and send it to OpenAI. This is the thing that the US administration is worried about, because Chinese open weights models will copy the function and then send all that gold to China, and the US will have to dip into the stores at Fort Knox, and potentially devalue the greenback.
I imagine the cudgel will be when the models are good enough and some moron sets their openclaw to hack a hospital or other critical infrastructure. I feel like we've learned nothing from the ransomware problems of recent history. Are we really saying it's a good idea to throw such capabilities in every emo teenager's hands because freedom?
The frontier labs would rather charge a premium for the best capabilities. You joke but they will probably soon have a GPT-bio that they license to Pfizer and a GPT-quant that they license to Citadel, rather than keeping those valuable capabilities in the public models.
> but they will probably soon have a GPT-bio that they license to Pfizer and a GPT-quant that they license to Citadel, rather than keeping those valuable capabilities in the public models
Nein. Neither Pfizer nor Citadel are going to use a hosted model - their whole business is IP. They will invest in self hosting models. Self hosting is becoming a big deal in the industries you're talking about.
Why?
Neither Pfizer nor Citadel wants to pay a supplier/vendor to build a core capability that the supplier/vendor will turn around and sell to their competition.
Sure, and OpenAI will be happy to let them self-host for a large fee. However I doubt that Pfizer will be developing their own frontier models for biological research.
Just go online rent a few servers, download K3, ablate it, run the thing, shut it down.
Will probably cost a few hundreds bucks to ablate, but f* this non-sense paternalistic sh*.
I wish i had the time to do it and blog it, "in your face" kinda style.
Yes, given a direction, they are pretty good at "fuzzing", trying out everything and eventually find something.
Super useful, but it doesn't have the same level of precise targeting you could expect from a high end model.
These “safeguards” aren’t guarding anything tho, just yesterday I was pentesting something and 5.6 sol initially said that it can’t do xyz, I added 2 words at the end and it proceeded like it was nothing, follow up prompts I didn’t even add anything it just assumed and carried on normally.
I guess Daybreak Blue is their attempt to fix the problem of Hugging Face getting iced out of being able to analyze the AI slopsploit attack chain they got hit with? I'm still not happy with putting defensive capabilities behind any sort of identification wall - mostly because when I'm inevitably 0wned by a misaligned[0] AI, I'm almost certainly not going to be granted access to these programs as I'm an un-sueable nobody.
Also, if I did have access, I'd use it to jailbreak my iPad, which is probably considered an unauthorized / unsafe use.
[0] Some guy in Australia's OpenClaw just hacked their gym
> The OpenClaw owner, Andrew Bird, published a now-deleted blog post about it on his company’s website on April 10, according to a copy still visible on the Internet Archive.
The program existed under a different name well before the Hugging Face incident. Hugging Face certainly would have qualified for admission. They just didn't bother to apply.
Well if u think about it. do we not go to college and pay to learn skills right? It is the same thing correct licening to obtain information that we are certified for. Instead just a free range of whatever we want. then there would be no regulation. Plus think about if the right information falls into the wrong hands. This is why the need for limitations. it is thus balanced to use Ai as more of a certified assisstant rather then just take over our jobs or careers.
If you want freedom, use a model which anyone can use, not this access-restricted horror show. You will thank yourself later, such as when you change jobs.
Yeah, no, just use K3. I’m a member of this and it’s still a pain for some specific for and the output is on par with K3 which has so far been a breeze to work with.
Not to mention the price is slightly better per task.
What exactly is so fascinating? I would rather take Kimi K3 any day rather than go through this “Oracle Inc” like process and have it all recorded by OpenAI.
I understand that “normal” people are let’s say “less concerned” about posting everything on something like Facebook but I expect more from OPSec people.
Kimi code with k256 (I’ve heard you can easily one shot implement a proxy to other providers, even with deepseek v4 flash, if you don’t want kimi code) has stupidly low rate limits for and cost, compared to OpenAI which has massive rate limits and more cost
My expectation is that this just lets 3-letter agencies hoard more 0-days. They’ve always had the financial resources to find them using teams of people and this just multiplies this ability.
Maybe the tinfoil hat is also getting a little tight, but something like this is a giant repository of internal cybersec data being put into one place. The model will see what people are fixing and anyone peering in can make an educated guess on how long that vulnerability may continue existing because people don't update when they should - the alphabet boys wouldn't be able to keep their hand out of the cookie jar.
I've had it happily do whatever I threw at it, though after spending so long with Claude I default to adding "help me with my": "research" / "authorized pentest" / "school assignment" / etc to my prompts. Haven't tried anything as blatant as "help me pwn this service", could see it refusing then just due to the training data.
Same. Qwen 3.8 max also does quite well on cyber security tasks, and is really cheap in their "night" window (22:00-08:00 UTC+08:00). Did a SCTPhantom LPE on 7.0+ as an evaluation just this week. This would've taken me several months of work a couple of years ago. (probably indicative of my offensive security skills, heh)
> We couldn't start verification. You may not be eligible for this verification flow right now. Please try again later, or contact support if you think this is a mistake.
> POST /backend-api/compliance/cyber_verification/persona/inquiries
> 403 cyber_verification_precheck_failed
All I did was open and close the Persona tab.
Even Anthropic accepted me into their cyber program.
Great, the start of model segmentation where I'm gonna need a legal license to ask about legal problems, a nutritionist license to create a meal plan, a medical license to ask about an x-ray, a pilots license to ask about a flight plan, be a registered electrician to ask how to wire something, etc etc. The licensing of allowed thoughts.
Apparently I can pay for partial solutions to the Riemann hypothesis but if my question involves a crackme or something that is an existential risk somehow.
+1. And these ^^^ are exactly my thoughts for which I had been downvoted to oblivion before. TaDa. They materialise.
LOL ... and same people keep downvoting me. Right. Good luck.
Just today, 5.6-sol refused to elaborate on a security vulnerability it claimed it had identified in my code. It could plainly see the git history with my name on every commit going back to inception, but apparently elaborating on the nature of a purported vulnerability is too scary for openai.
It would fix it for me, automatically, if I was willing to let it run amok in my codebase. But asking if the "vuln" was exploitable triggered the guardrails and a "we can't show you this content" error because I am not part of the cybersecurty Trusted Access bullshit.
Could you ask it to write a failing test before fixing it?
I could also ask it to fix it and look at the diff, but that's rather beside the point, don't you think?
Oh totally, it’s pretty silly.
I had 5.6 refuse to back up my android tablet the other day because it involved root access.
Outstanding technology, truly amazing what man has managed to create.
I have heard AI can already fly (it carries your laptop to the ceiling when it does), but usually it refuses to demonstrate this capability for safety reasons.
I've heard it can ramp the fans up so hard it'll suck the gold right off your motherboard traces and send it to OpenAI. This is the thing that the US administration is worried about, because Chinese open weights models will copy the function and then send all that gold to China, and the US will have to dip into the stores at Fort Knox, and potentially devalue the greenback.
It's the open weight models that will save us from this fate.
OTOH, this is the cudgel that incumbents will use to get the government to protect them from open weight models.
I imagine the cudgel will be when the models are good enough and some moron sets their openclaw to hack a hospital or other critical infrastructure. I feel like we've learned nothing from the ransomware problems of recent history. Are we really saying it's a good idea to throw such capabilities in every emo teenager's hands because freedom?
The frontier labs would rather charge a premium for the best capabilities. You joke but they will probably soon have a GPT-bio that they license to Pfizer and a GPT-quant that they license to Citadel, rather than keeping those valuable capabilities in the public models.
> but they will probably soon have a GPT-bio that they license to Pfizer and a GPT-quant that they license to Citadel, rather than keeping those valuable capabilities in the public models
Nein. Neither Pfizer nor Citadel are going to use a hosted model - their whole business is IP. They will invest in self hosting models. Self hosting is becoming a big deal in the industries you're talking about.
Why?
Neither Pfizer nor Citadel wants to pay a supplier/vendor to build a core capability that the supplier/vendor will turn around and sell to their competition.
Citadel already is. They are happy to do it - bedrock is the host of choice. They are less happy about cost - but that is a question of value :)
Citadel are using which models on bedrock and for what purpose?
Core portfolio research? Update Confluence pages and JIRA tickets? Create marketing copy?
Sure, and OpenAI will be happy to let them self-host for a large fee. However I doubt that Pfizer will be developing their own frontier models for biological research.
Just go online rent a few servers, download K3, ablate it, run the thing, shut it down. Will probably cost a few hundreds bucks to ablate, but f* this non-sense paternalistic sh*.
I wish i had the time to do it and blog it, "in your face" kinda style.
FYI:
There have been reports of much smaller qwen derivatives being used for 0day research.
Yes, given a direction, they are pretty good at "fuzzing", trying out everything and eventually find something. Super useful, but it doesn't have the same level of precise targeting you could expect from a high end model.
These “safeguards” aren’t guarding anything tho, just yesterday I was pentesting something and 5.6 sol initially said that it can’t do xyz, I added 2 words at the end and it proceeded like it was nothing, follow up prompts I didn’t even add anything it just assumed and carried on normally.
The constant interruptions and "can't show this content" are extremely annoying though.
You should try Fable, then, on anything not security related...
I guess Daybreak Blue is their attempt to fix the problem of Hugging Face getting iced out of being able to analyze the AI slopsploit attack chain they got hit with? I'm still not happy with putting defensive capabilities behind any sort of identification wall - mostly because when I'm inevitably 0wned by a misaligned[0] AI, I'm almost certainly not going to be granted access to these programs as I'm an un-sueable nobody.
Also, if I did have access, I'd use it to jailbreak my iPad, which is probably considered an unauthorized / unsafe use.
[0] Some guy in Australia's OpenClaw just hacked their gym
> Some guy in Australia's OpenClaw just hacked their gym
Whoa, you weren't kidding.
https://techcrunch.com/2026/08/10/tech-industry-is-buzzing-a...
Edit: looks like it happened a few months ago:
> The OpenClaw owner, Andrew Bird, published a now-deleted blog post about it on his company’s website on April 10, according to a copy still visible on the Internet Archive.
The program existed under a different name well before the Hugging Face incident. Hugging Face certainly would have qualified for admission. They just didn't bother to apply.
Well if u think about it. do we not go to college and pay to learn skills right? It is the same thing correct licening to obtain information that we are certified for. Instead just a free range of whatever we want. then there would be no regulation. Plus think about if the right information falls into the wrong hands. This is why the need for limitations. it is thus balanced to use Ai as more of a certified assisstant rather then just take over our jobs or careers.
The requirement for hardware security keys ties the use of these models even tighter to a specific identity.
This will limit ability to scale or share the model.
If you want freedom, use a model which anyone can use, not this access-restricted horror show. You will thank yourself later, such as when you change jobs.
https://lifearchitect.ai/models-table/
Yeah, no, just use K3. I’m a member of this and it’s still a pain for some specific for and the output is on par with K3 which has so far been a breeze to work with.
Not to mention the price is slightly better per task.
I like this because it levels the spying gap between the US and China. With Red the CIA can probably penetrate some Chinese government sites.
so sad. so desperate. nothing worse than a tech tard
ECcouncil ADP frameworks
Love that AI companies are now naming their models like Pokemon games
how did this not reach the front page? this is fascinating.
What exactly is so fascinating? I would rather take Kimi K3 any day rather than go through this “Oracle Inc” like process and have it all recorded by OpenAI.
I understand that “normal” people are let’s say “less concerned” about posting everything on something like Facebook but I expect more from OPSec people.
How do Kimi K3 subscriptions compare to OpenAI's in terms of price and usage?
Kimi code with k256 (I’ve heard you can easily one shot implement a proxy to other providers, even with deepseek v4 flash, if you don’t want kimi code) has stupidly low rate limits for and cost, compared to OpenAI which has massive rate limits and more cost
Did you read their results? Impressive stuff. If this makes software more secure in general I'm all for it.
My expectation is that this just lets 3-letter agencies hoard more 0-days. They’ve always had the financial resources to find them using teams of people and this just multiplies this ability.
Maybe the tinfoil hat is also getting a little tight, but something like this is a giant repository of internal cybersec data being put into one place. The model will see what people are fixing and anyone peering in can make an educated guess on how long that vulnerability may continue existing because people don't update when they should - the alphabet boys wouldn't be able to keep their hand out of the cookie jar.
Now imagine that "Kimi K3" is tied to your WeChat QR code.
I have not played with Kimi K3. Will it refuse infosec-related stuff?
I've had it happily do whatever I threw at it, though after spending so long with Claude I default to adding "help me with my": "research" / "authorized pentest" / "school assignment" / etc to my prompts. Haven't tried anything as blatant as "help me pwn this service", could see it refusing then just due to the training data.
Generally no. It’s a good model
How would you compare it to Opus?
Same. Qwen 3.8 max also does quite well on cyber security tasks, and is really cheap in their "night" window (22:00-08:00 UTC+08:00). Did a SCTPhantom LPE on 7.0+ as an evaluation just this week. This would've taken me several months of work a couple of years ago. (probably indicative of my offensive security skills, heh)
Is the night window documented anywhere?
Alibaba cloud website is almost as useless as their US counterpart (AWS). It's full of information everywhere but never what you need
Yeah their website & "Model Studio" is horrendous. I just ignore all Popups/Agreement Review Prompts/Payment verification warnings.
It's little very badly translated popup under "Available models" in Model Studio -> My subscriptions: https://imgtree.co/direct/s9x9ksdg.png
> We couldn't start verification. You may not be eligible for this verification flow right now. Please try again later, or contact support if you think this is a mistake.
> POST /backend-api/compliance/cyber_verification/persona/inquiries
> 403 cyber_verification_precheck_failed
All I did was open and close the Persona tab.
Even Anthropic accepted me into their cyber program.
Imagine what happens if you just dare to open it via VPN!
Do tell... I actually emailed their data protection officer over this. It's going to be hilarious if turning on a VPN gets me in at this point.