Hacker Newsnew | past | comments | ask | show | jobs | submit | blazespin's commentslogin

Are there terms clear? I dunno. There are ways to train on API usage without training on API usage.


yeah, is it API or codex?


Poor wording on my end, thanks for flagging. I pull the OAuth refresh token from each Codex account into a custom broker, which mints short-lived access tokens per request and load-balances across the pool.


I think the point is less "how can we throw shade on the OP" and more "a harness can enable a lot of models to do very serious cybersec, glm 5.2 is one of them"


Are you replying to a response to the original comment? I looked but i didn't see anyone saying he's throwing shade.


You have to forgive the GLM bot. It's not very good.


Yeah, I am seeing this as well, especially as people use AI to code review stuff more so this sort of thing slips through. On one very large project I am looking at, it's already becoming harder to find issues.

These people whinging about slop don't realize everything that doesn't come from a credible source gets ignored.

Credible people are using AI and once these issues are fixed, it will die down.

The threat of AI zero days will persist though, but they will be much more expensive and subtle to find.


Just optimized AI driven fuzzing. Do a search on arxiv you'll find a lot.


I have a dozen or so critical CVEs now, it's not hard to believe at all if they're just hardening tasks. I can get a dozen hardening tasks from just one prompt. I don't even bother filing them as the critical ones are more important right now.


This is ludicrous logic. We already know that there is an AI firehose. You don't need to do this. They should have used proper disclosure.

All this is doing is making the AI firehose worse.


You are assuming that most projects are responsive in today’s ai firehose climate. They are not. This at least Tells users of those Projects to either find developers or write their own.

I’m onboard with this being suboptimal. But as someone who has filed >10 significant disclosures in the last month resulting from reviewing my codebase and had exactly zero responses, I can relate to the decision.


Pretty soon I suspect, otherwise Chinese models are going to have free reign to develop brand goodwill. Question is how this impacts the international posture.


They already did and a ban is practically difficult if not impossible to enforce. People resell tokens and compute.


Ban on Chinese models is coming on pretty soon. Seems unlikely they're going to shut down openAI and anthropic, but not foreign models.


This will be a fun watch, because other countries won't rush to ban Chinese models. Fun times, fun times.


The hilarious thing here is anthropic is basically admitting that most of their Capabilities can be easily copied.


I listened to a podcast on Ai and security today where they said they got access to a hackers workdir (after they were caught) and they had hacked 14 companies using GPT-5.2 and Claude <4.5 (forget minor). GLM-5.2 came up because, while not as good as Mythos, it's almost as good, i.e. you have to prompt more / cannot just give a fuzzy request and sit back. The harness likely matters more than the model

https://www.youtube.com/watch?v=ldEJq_JxYuM


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: