GPT 5.6 Cyber

(openai.com)

117 points | by gizmodo59 21 hours ago

16 comments

  • xyzzy123 15 hours ago
    Great, the start of model segmentation where I'm gonna need a legal license to ask about legal problems, a nutritionist license to create a meal plan, a medical license to ask about an x-ray, a pilots license to ask about a flight plan, be a registered electrician to ask how to wire something, etc etc. The licensing of allowed thoughts.

    Apparently I can pay for partial solutions to the Riemann hypothesis but if my question involves a crackme or something that is an existential risk somehow.

    • pants2 2 hours ago
      The frontier labs would rather charge a premium for the best capabilities. You joke but they will probably soon have a GPT-bio that they license to Pfizer and a GPT-quant that they license to Citadel, rather than keeping those valuable capabilities in the public models.
      • subhobroto 2 hours ago
        > but they will probably soon have a GPT-bio that they license to Pfizer and a GPT-quant that they license to Citadel, rather than keeping those valuable capabilities in the public models

        Nein. Neither Pfizer nor Citadel are going to use a hosted model - their whole business is IP. They will invest in self hosting models. Self hosting is becoming a big deal in the industries you're talking about.

        Why?

        Neither Pfizer nor Citadel wants to pay a supplier/vendor to build a core capability that the supplier/vendor will turn around and sell to their competition.

        • foobar10000 1 hour ago
          Citadel already is. They are happy to do it - bedrock is the host of choice. They are less happy about cost - but that is a question of value :)
          • subhobroto 1 hour ago
            Citadel are using which models on bedrock and for what purpose?

            Core portfolio research? Update Confluence pages and JIRA tickets? Create marketing copy?

        • pants2 1 hour ago
          Sure, and OpenAI will be happy to let them self-host for a large fee. However I doubt that Pfizer will be developing their own frontier models for biological research.
    • bryanlarsen 10 hours ago
      It's the open weight models that will save us from this fate.

      OTOH, this is the cudgel that incumbents will use to get the government to protect them from open weight models.

    • stackghost 12 hours ago
      Just today, 5.6-sol refused to elaborate on a security vulnerability it claimed it had identified in my code. It could plainly see the git history with my name on every commit going back to inception, but apparently elaborating on the nature of a purported vulnerability is too scary for openai.

      It would fix it for me, automatically, if I was willing to let it run amok in my codebase. But asking if the "vuln" was exploitable triggered the guardrails and a "we can't show you this content" error because I am not part of the cybersecurty Trusted Access bullshit.

      • graceful6800 11 hours ago
        I had 5.6 refuse to back up my android tablet the other day because it involved root access.

        Outstanding technology, truly amazing what man has managed to create.

        • DoctorOetker 10 hours ago
          I have heard AI can already fly (it carries your laptop to the ceiling when it does), but usually it refuses to demonstrate this capability for safety reasons.
          • anakaine 5 hours ago
            I've heard it can ramp the fans up so hard it'll suck the gold right off your motherboard traces and send it to OpenAI. This is the thing that the US administration is worried about, because Chinese open weights models will copy the function and then send all that gold to China, and the US will have to dip into the stores at Fort Knox, and potentially devalue the greenback.
      • ch4s3 11 hours ago
        Could you ask it to write a failing test before fixing it?
        • stackghost 11 hours ago
          I could also ask it to fix it and look at the diff, but that's rather beside the point, don't you think?
          • ch4s3 10 minutes ago
            Oh totally, it’s pretty silly.
    • siva7 15 hours ago
      [flagged]
      • culi 13 hours ago
        Nobody wants to license programming. The skillsets are far too diverse and rapidly changing anyways. What programmers could use though is a union
      • mexicojalisco 15 hours ago
        Furthermore everybody should need a license from the government or industry to cook morning breakfast on the stove. Fire hazards and all. Could do real harm if something went wrong.
        • copperx 15 hours ago
          You do need a license to sell food in most countries.
          • DaSHacka 7 hours ago
            What about just producing food?
      • hbosch 15 hours ago
        How much will a license cost? Can it be earned? If granted, granted by whom? Can I use it across models? Does it need to be reassessed regularly? How often?

        If any of the above are more convenient than paying an engineer you aren’t any safer, the enterprise paying is just putting money in someone else’s pocket.

        • sroussey 14 hours ago
          Most engineers have licenses in the engineering discipline, except Electric Engineers. Mechanical and Civil. Engineering is based on the constraints of physics thus applied to mankind uses. Now if you talk about software "engineers" (as i am one), that is quite fast and loose.

          Based on the damage done in some sectors, it would be interesting to see an alternative history where software required licenses and degrees. Certainly, the larger tech ecosystem would have moved more slowly, and products more expensive.

          While EE are basically held accountable by their employers, and the physics of it all requiring that things work correctly, software developers don't have the same kind of feedback loop. Thus any country that did not play into that system would compete on features over quality. I don't think that would have lasted. Same issue with "pausing" AI development in one country.

          • stackghost 12 hours ago
            >While EE are basically held accountable by their employers

            Licensed engineers are technically held accountable by their peers. The definition of a profession (versus just a job) is that professionals as a group are self-regulating. That is why e.g. doctors can be disciplined by their College, and lawyers can be disbarred by the legal society.

            This is because Professional Engineering is actually a social process, not really a technical one. The work is technical, sure, but the reason we have Professional Engineers is because society realized long ago that letting any idiot build e.g. a bridge for public traffic is a bad idea.

            Society, via legislation, grants professional licensing bodies special privileges in return for exerting control over the practising members of that profession.

            The reason you don't see as many EEs (or aerospace) engineers with PEs is because the products that get produced in those specialties get certified in different ways. There's no bridge equivalent to the FCC, for example.

          • idiotsecant 13 hours ago
            There are definitely a ton of PE electrical engineers. The power industry - transmission, generation, distribution, is rife with them.
            • vel0city 12 hours ago
              I do agree there's tons of PE electrical engineers. I also think there's a massive number of job roles which relate to a BS/MS EE degrees where nobody really gives a shit if you have a stamp or not.
      • matheusmoreira 14 hours ago
        > just like lawyers or doctors won't

        Pretty big assumption.

      • bellowsgulch 13 hours ago
        I don't want this, but I do get what you're saying. What I really want is software engineers in our industry to stop behaving like such idiot losers who are begging to be jobless and give everything away for free.

        Doctors protect doctor's interests. Lawyers aren't idiots, they're professionals who run businesses with the express intent to make money.

        Software engineers seem to be just bright enough to make money, and just stupid enough to say, no no, please I'd prefer to be homeless, please take my job and automate me, offshore me, and devalue my salary out of existence all at once.

        • derektank 12 hours ago
          >Doctors protect doctor's interests. Lawyers aren't idiots, they're professionals who run businesses with the express intent to make money.

          And this is generally a bad thing, to be clear. It often comes in the form of rent seeking which should be fought tooth and nail by the rest of society.

          • bellowsgulch 11 hours ago
            Yeah, we should let H1Bs take everyone's jobs, not just software engineers! Great idea, Bob!
        • AbbeFaria 10 hours ago
          It’s the nature of our jobs. The artefacts we produce, code and documentation are out in the open, available freely for training LLMs.

          That’s not true for highly qualified doctors, patient case histories, patient feedback that helps doctors diagnose or treat patients or for surgeons to operate on patients. All of these actions are high stakes, get it wrong and people could die, AI would never be able to replace them.

      • prettyblocks 12 hours ago
        In what dystopian black mirror alternate reality can anyone possibly perceive this as saving the profession of programming? It sounds like hell.
      • mpalmer 13 hours ago
        That would be doing the wrong thing for precisely the wrong reasons.
      • xyzzy123 14 hours ago
        I can't tell if your comment is satire or not, so, bravo :)

        From my perspective what I always loved about "the profession" was a relative LACK of gatekeeping. I loved offensive security for the same reason, there was a long run where you really just needed to be able to hack, and if you could demonstrate that there was a job for you somewhere (for better or worse).

        Keeping the industry in its current form frozen in amber would be as weird as, I don't know, keeping horses & carriages in business by regulating scarcity of motor vehicle licenses. Not a great analogy but hopefully you see what I mean.

    • RealWed5 13 hours ago
      +1. And these ^^^ are exactly my thoughts for which I had been downvoted to oblivion before. TaDa. They materialise.
      • RealWed5 8 hours ago
        LOL ... and same people keep downvoting me. Right. Good luck.
  • _davide_ 5 hours ago
    Just go online rent a few servers, download K3, ablate it, run the thing, shut it down. Will probably cost a few hundreds bucks to ablate, but f* this non-sense paternalistic sh*.

    I wish i had the time to do it and blog it, "in your face" kinda style.

    • throwa356262 5 hours ago
      FYI:

      There have been reports of much smaller qwen derivatives being used for 0day research.

      • _davide_ 5 hours ago
        Yes, given a direction, they are pretty good at "fuzzing", trying out everything and eventually find something. Super useful, but it doesn't have the same level of precise targeting you could expect from a high end model.
  • intern4tional 14 hours ago
    The requirement for hardware security keys ties the use of these models even tighter to a specific identity.

    This will limit ability to scale or share the model.

  • kharma414 11 hours ago
    Well if u think about it. do we not go to college and pay to learn skills right? It is the same thing correct licening to obtain information that we are certified for. Instead just a free range of whatever we want. then there would be no regulation. Plus think about if the right information falls into the wrong hands. This is why the need for limitations. it is thus balanced to use Ai as more of a certified assisstant rather then just take over our jobs or careers.
  • adt 15 hours ago
  • ofjcihen 1 hour ago
    Yeah, no, just use K3. I’m a member of this and it’s still a pain for some specific for and the output is on par with K3 which has so far been a breeze to work with.

    Not to mention the price is slightly better per task.

  • dash2 14 hours ago
    I like this because it levels the spying gap between the US and China. With Red the CIA can probably penetrate some Chinese government sites.
  • tamimio 15 hours ago
    These “safeguards” aren’t guarding anything tho, just yesterday I was pentesting something and 5.6 sol initially said that it can’t do xyz, I added 2 words at the end and it proceeded like it was nothing, follow up prompts I didn’t even add anything it just assumed and carried on normally.
    • matheusmoreira 14 hours ago
      The constant interruptions and "can't show this content" are extremely annoying though.
  • soundworlds 12 hours ago
    Love that AI companies are now naming their models like Pokemon games
  • kmeisthax 12 hours ago
    I guess Daybreak Blue is their attempt to fix the problem of Hugging Face getting iced out of being able to analyze the AI slopsploit attack chain they got hit with? I'm still not happy with putting defensive capabilities behind any sort of identification wall - mostly because when I'm inevitably 0wned by a misaligned[0] AI, I'm almost certainly not going to be granted access to these programs as I'm an un-sueable nobody.

    Also, if I did have access, I'd use it to jailbreak my iPad, which is probably considered an unauthorized / unsafe use.

    [0] Some guy in Australia's OpenClaw just hacked their gym

    • javawizard 12 hours ago
      > Some guy in Australia's OpenClaw just hacked their gym

      Whoa, you weren't kidding.

      https://techcrunch.com/2026/08/10/tech-industry-is-buzzing-a...

      Edit: looks like it happened a few months ago:

      > The OpenClaw owner, Andrew Bird, published a now-deleted blog post about it on his company’s website on April 10, according to a copy still visible on the Internet Archive.

  • kharma414 11 hours ago
    ECcouncil ADP frameworks
  • OutOfHere 12 hours ago
    If you want freedom, use a model which anyone can use, not this access-restricted horror show. You will thank yourself later, such as when you change jobs.
  • derac 17 hours ago
    how did this not reach the front page? this is fascinating.
    • theplumber 16 hours ago
      What exactly is so fascinating? I would rather take Kimi K3 any day rather than go through this “Oracle Inc” like process and have it all recorded by OpenAI.

      I understand that “normal” people are let’s say “less concerned” about posting everything on something like Facebook but I expect more from OPSec people.

      • dTP90pN 1 hour ago
        Same. Qwen 3.8 max also does quite well on cyber security tasks, and is really cheap in their "night" window (22:00-08:00 UTC+08:00). Did a SCTPhantom LPE on 7.0+ as an evaluation just this week. This would've taken me several months of work a couple of years ago. (probably indicative of my offensive security skills, heh)
        • throwa356262 1 hour ago
          Is the night window documented anywhere?

          Alibaba cloud website is almost as useless as their US counterpart (AWS). It's full of information everywhere but never what you need

      • RealWed5 13 hours ago
        Now imagine that "Kimi K3" is tied to your WeChat QR code.
      • matheusmoreira 15 hours ago
        How do Kimi K3 subscriptions compare to OpenAI's in terms of price and usage?
        • Footprint0521 13 hours ago
          Kimi code with k256 (I’ve heard you can easily one shot implement a proxy to other providers, even with deepseek v4 flash, if you don’t want kimi code) has stupidly low rate limits for and cost, compared to OpenAI which has massive rate limits and more cost
      • derac 13 hours ago
        Did you read their results? Impressive stuff. If this makes software more secure in general I'm all for it.
        • bathtub365 12 hours ago
          My expectation is that this just lets 3-letter agencies hoard more 0-days. They’ve always had the financial resources to find them using teams of people and this just multiplies this ability.
          • weakened_malloc 12 hours ago
            Maybe the tinfoil hat is also getting a little tight, but something like this is a giant repository of internal cybersec data being put into one place. The model will see what people are fixing and anyone peering in can make an educated guess on how long that vulnerability may continue existing because people don't update when they should - the alphabet boys wouldn't be able to keep their hand out of the cookie jar.
      • stackghost 11 hours ago
        I have not played with Kimi K3. Will it refuse infosec-related stuff?
        • DaSHacka 7 hours ago
          I've had it happily do whatever I threw at it, though after spending so long with Claude I default to adding "help me with my": "research" / "authorized pentest" / "school assignment" / etc to my prompts. Haven't tried anything as blatant as "help me pwn this service", could see it refusing then just due to the training data.
  • surcap526 6 hours ago
    [dead]
  • surcap526 6 hours ago
    [dead]
  • matheusmoreira 15 hours ago
    > We couldn't start verification. You may not be eligible for this verification flow right now. Please try again later, or contact support if you think this is a mistake.

    > POST /backend-api/compliance/cyber_verification/persona/inquiries

    > 403 cyber_verification_precheck_failed

    All I did was open and close the Persona tab.

    Even Anthropic accepted me into their cyber program.

    • RealWed5 13 hours ago
      Imagine what happens if you just dare to open it via VPN!
      • matheusmoreira 10 hours ago
        Do tell... I actually emailed their data protection officer over this. It's going to be hilarious if turning on a VPN gets me in at this point.