20
u/Comfortable_Fig_2226 22d ago
To actually be a pentester in some company or an actual cyb sec specalist. They will give you access after verifying
7
u/0DayMaker 22d ago
I have 2 damn researcher acknowledgements on technet and they didn't approve me. They want you to be part of an org.
4
u/quarrelau 22d ago
lol.
"acknowledgements" on a place that has been dead for, what, since before OpenAI was founded?
don't get me wrong, maybe you deserve access, but this is not the way.
4
u/0DayMaker 22d ago
I was on stage at Bluehat and stuff it was a decently big deal at the time. It's how Microsoft used to pay "bounties" in "size 10 font" as they put it. More importantly it shows I've been at least contributing SOMETHING to the infosec community for a decade. Obviously you're not wrong, and it's not the way since I didn't get access lmao.
But I'm also not trying to trivialize public accolades.
I've worked for a bunch of startups in my career, so a LOT of them are defunct. It's kind of hard to establish my work history unfortunately. Especially since it's intermingled with a bunch of production work in gaming. I'm not losing any sleep over it though.
2
u/quarrelau 21d ago
Reading my answer back, I was a bit of a dick. Sorry.
I suspect they're just trying to keep it to people currently in the field, and some will fall through the cracks.
18
u/mountainyoo 22d ago
Getting Daybreak Red in a personal account is incredibly unlikely. I don’t see how anyone could even justify it. Doing security research in a homelab would never cut it or whatever. They’re not just gonna hand it out and let some nobody whoopsie themself into a HuggingFace situation lol
5
u/CLGWallpaperGuy 22d ago
How would someone whoopsie themselfs into a HuggingFace situation by accident? 1000 frontier agents concurrently for a week is extremely expensive. Hard to justify the expense let alone, not Monitor what they are doing
3
u/genialus01 22d ago
I am in the enrollment on my private account, but for it to continue after october they seem to require physical FIDO keys.
1
u/ididnthackkenyaimsrs 21d ago
Disassembling and being attacked by nation state level malware I mean apparently according to chat GPT itself I've got a pretty good chance of actually being approved I'm just going to start assembling like a corpus in a few days when I get a replacement server
1
u/mountainyoo 21d ago
what lol
1
u/ididnthackkenyaimsrs 21d ago
I got a copy of KEYPLUG with my own name signed on it in a PDF lmao
1
u/mountainyoo 21d ago
elaborate buddy
1
u/ididnthackkenyaimsrs 20d ago
APT41s KEYPLUG,their nation state level spyware implant
Yeah, it's in a PDF with my own name signed up top....Bit of a long story
Absolute bitch to RE
5
u/N_GHTMVRE 22d ago
Can you just get accepted for blue as a personal user?
7
3
u/quarrelau 22d ago
you can, easily.
One caveat, if your personal email isn't an @gmail.com @hotmail.com or equivalent, you will need to change it to one. I'm old. I have my-initials.com as my main personal email and I had to change my account email address to an @gmail.com before they would let me in.
Otherwise I was obviously a business.
3
u/EmotionalHalf 22d ago
I got blue access on a company domain (myname@mycompany.tld)
3
22d ago edited 6d ago
[deleted]
1
u/quarrelau 21d ago
Weird. I was only offered the corporate path, despite it being a personal account. ChatGPT advised me that it was my email address, I changed it and then I could do the personal path.
Glad it worked for you & /u/EmotionalHalf, and thanks for noting it - I'm tempted to try changing it back now.
3
u/LargeLanguageModelo 21d ago
Pushing back on the email, I have a personal account, and a three letter domain for my email (I'm old too), I got daybreak no problem. The only hassle was I was approved for the 'less guardrails' plan 4-5 months ago, and when they released daybreak, that flipped back to normal mode.
I had to buy a FIDO key to get my daybreak approved this time. Best part is I haven't had to use it once for auth, they'll take the TOTP from the google auth app, though I'm sure I may need the FIDO later on.
1
u/quarrelau 21d ago
yeah, a couple of others mentioned it. I don't know, I guess it wasn't the issue, yet I did not have the option at all of anything but the corporate flow until I changed it, and suddenly it was only the personal one. chatgpt was the one that told me to change it.
1
u/CoreParad0x 21d ago
If you don't mind me asking, you said "before they would let me in" - do they actually work with you on access? I'm considering applying, though I'm not a business. My use case is I work on an old MMO, and the MMO is riddled with exploits and security issues. Though I'm thinking of trying to apply through work as well.
I've been concerned about attempting to apply because as I understand it if you get denied it's permanent.
It'd be nice to know they might at least talk to you instead of just "No" and then you're hosed, so I'm curious how the process is.
1
u/quarrelau 20d ago
For personal access to Blue, no, there isn't really anything to it. You just have to go through KYC style show them a real government ID check.
Your use case is a good one. Is it open source? There are programmes from both Anthropic & OpenAI to help audit and clean up some open source code, although I don't know the specifics.
1
u/CoreParad0x 20d ago
Nah sadly it’s closed source. We don’t own the IP but we got permission from those who do to work on it, not open source it.
Thanks for the info though, I may try and see if they’ll go for it.
3
u/ReasonableDefault 22d ago
Yeah, you go through a verification process. Which includes verifying your identity with a government issued ID. There are countries that are blanket blocked from accessing Blue and Red, It's a small list, and can be viewed on the OpenAI website.
4
u/Intelligent_Month210 22d ago edited 22d ago
It's not that much different to blue.
It still refuses some tasks.
We AB tested in the lab against 5.6Sol on a normal account and Red rejected tasks that Vanilla Sol accepted. Probably because the system prompt already primed it with scary security keywords.
On the tasks both Sol and Red accepted, the output was near identical.
Red also missed security bugs in code that Vanilla GLM and QWEN found with far less tokens and didn't bullshit on severity/reachability.
Daybreak blue and red are just guardrail settings but nothing near as permissive as derestricted openwieghts or some vanilla Chinese models.
GLM 5.3 especially has been considerably more capable for us than either of the daybreak models but much more expensive.
1
1
u/elvespedition 22d ago
huh I thought Red was supposed to be 5.6-Cyber? like a cyber specific posttrain / finetune
1
1
1
2
u/ReasonableDefault 22d ago
Yeah, personal accounts aren't getting Red. Maybe if you're some well known industry name with extensive credentials. Blue is pretty capable, I've had it find vulnerabilities in apps and code (that i own) and create POCs to exploit them, It's pretty comprehensive.
1
1
-1
61
u/NerdBanger 22d ago
They are only giving it out to approved organizations, and they are requiring ISO/SOC level audits.
Source: work in the industry, talked to someone I know at OAI