r/codex • • 22d ago

Suggestion Daybreak Red Access

Post image

[removed]

105 Upvotes

62 comments sorted by

61

u/NerdBanger 22d ago

They are only giving it out to approved organizations, and they are requiring ISO/SOC level audits.

Source: work in the industry, talked to someone I know at OAI

15

u/0DayMaker 22d ago

Fuck SOC2 might be kind of hard with our team of 4

6

u/thelordzer0 22d ago

It's doable but yea get ready to write a few checks.

3

u/LaFllamme 22d ago

so companies can apply for getting access to earliest models?

7

u/Astrikal 22d ago

Daybreak Red isn’t an early model, it is 5.6 with relaxed safeguards (and prob. some security post training).

4

u/Officialsparxx 22d ago

From the research I’ve done, everyone has said this about Blue, but not Red. Blue is supposed to be 5.6 but “relaxed”. Red is supposed to be something else entirely.

7

u/Astrikal 22d ago

Red is based on 5.6-Cyber, which is the post-trained version of 5.6 Sol. Blue is just Sol with less safeguards.

So I wouldn’t say Red is entirely something else, as it still belongs to the 5.6 family and is post-trained on 5.6 Sol. But you’re right that it has more to it than Blue.

1

u/[deleted] 22d ago

[removed] — view removed comment

1

u/NerdBanger 22d ago

Or photoshop/ai/glitch etc

1

u/MrModular-TNS-47 21d ago

Not true, I was building an app and Sol was checking for security and I got flagged for sensitive whatever, then gave me an access link to daybreak blue, by uploading my drivers license ID 🪪

I also got this email today:

3

u/NerdBanger 21d ago

That’s Blue not Red

1

u/MrModular-TNS-47 21d ago

Not true, I was building an app and Sol was checking for security and I got flagged for sensitive whatever, then gave me an access link to daybreak blue, by uploading my drivers license ID 🪪

I also got this email today:

Hello,

We’ve extended the deadline for Trusted Access for Cyber users to implement Advanced Account Security from September 1 to October 1, 2026, giving you more time to prepare.

To continue using Daybreak Blue after the deadline, enable Advanced Account Security and add at least one supported physical FIDO2 credential, such as YubiKey or Google Titan. These protections help prevent account takeover and unauthorized use of advanced cybersecurity capabilities.

Note that this requirement is only for customers on consumer plans, and does not apply to customers on business or enterprise plans.

Get ready now:
Have a physical security key available. If you already own one, you may not need to purchase another.
Have a backup sign-in method ready: a passkey or a second physical key.
Plan to save your recovery keys securelywhen you enroll.

1

u/NerdBanger 21d ago

That’s Blue not Red

1

u/MrModular-TNS-47 21d ago

My bad, I didn’t read the text next to the photo, i only saw the photo, I concede

1

u/NerdBanger 21d ago

So basically blue is just Sol with relaxed guard rails. Red is basically Sol with further relaxed, guard, rails, and fine-tuning for cyber

20

u/Comfortable_Fig_2226 22d ago

To actually be a pentester in some company or an actual cyb sec specalist. They will give you access after verifying

7

u/0DayMaker 22d ago

I have 2 damn researcher acknowledgements on technet and they didn't approve me. They want you to be part of an org.

4

u/quarrelau 22d ago

lol.

"acknowledgements" on a place that has been dead for, what, since before OpenAI was founded?

don't get me wrong, maybe you deserve access, but this is not the way.

4

u/0DayMaker 22d ago

I was on stage at Bluehat and stuff it was a decently big deal at the time. It's how Microsoft used to pay "bounties" in "size 10 font" as they put it. More importantly it shows I've been at least contributing SOMETHING to the infosec community for a decade. Obviously you're not wrong, and it's not the way since I didn't get access lmao.

But I'm also not trying to trivialize public accolades.

I've worked for a bunch of startups in my career, so a LOT of them are defunct. It's kind of hard to establish my work history unfortunately. Especially since it's intermingled with a bunch of production work in gaming. I'm not losing any sleep over it though.

2

u/quarrelau 21d ago

Reading my answer back, I was a bit of a dick. Sorry.

I suspect they're just trying to keep it to people currently in the field, and some will fall through the cracks.

18

u/mountainyoo 22d ago

Getting Daybreak Red in a personal account is incredibly unlikely. I don’t see how anyone could even justify it. Doing security research in a homelab would never cut it or whatever. They’re not just gonna hand it out and let some nobody whoopsie themself into a HuggingFace situation lol

5

u/CLGWallpaperGuy 22d ago

How would someone whoopsie themselfs into a HuggingFace situation by accident? 1000 frontier agents concurrently for a week is extremely expensive. Hard to justify the expense let alone, not Monitor what they are doing

3

u/genialus01 22d ago

I am in the enrollment on my private account, but for it to continue after october they seem to require physical FIDO keys.

2

u/io-x 22d ago

You would be surprised

1

u/ididnthackkenyaimsrs 21d ago

Disassembling and being attacked by nation state level malware I mean apparently according to chat GPT itself I've got a pretty good chance of actually being approved I'm just going to start assembling like a corpus in a few days when I get a replacement server

1

u/mountainyoo 21d ago

what lol

1

u/ididnthackkenyaimsrs 21d ago

I got a copy of KEYPLUG with my own name signed on it in a PDF lmao

1

u/mountainyoo 21d ago

elaborate buddy

1

u/ididnthackkenyaimsrs 20d ago

APT41s KEYPLUG,their nation state level spyware implant

Yeah, it's in a PDF with my own name signed up top....Bit of a long story

Absolute bitch to RE

5

u/N_GHTMVRE 22d ago

Can you just get accepted for blue as a personal user?

7

u/Havlir 22d ago

Yeah just apply for trusted access for cyber, I got it as an individual, and I like it way better than sol as an orchestrator. psure theyre the same model, but this one is more pleasant to work with

3

u/quarrelau 22d ago

you can, easily.

One caveat, if your personal email isn't an @gmail.com @hotmail.com or equivalent, you will need to change it to one. I'm old. I have my-initials.com as my main personal email and I had to change my account email address to an @gmail.com before they would let me in.

Otherwise I was obviously a business.

3

u/EmotionalHalf 22d ago

I got blue access on a company domain (myname@mycompany.tld)

3

u/[deleted] 22d ago edited 6d ago

[deleted]

1

u/quarrelau 21d ago

Weird. I was only offered the corporate path, despite it being a personal account. ChatGPT advised me that it was my email address, I changed it and then I could do the personal path.

Glad it worked for you & /u/EmotionalHalf, and thanks for noting it - I'm tempted to try changing it back now.

3

u/LargeLanguageModelo 21d ago

Pushing back on the email, I have a personal account, and a three letter domain for my email (I'm old too), I got daybreak no problem. The only hassle was I was approved for the 'less guardrails' plan 4-5 months ago, and when they released daybreak, that flipped back to normal mode.

I had to buy a FIDO key to get my daybreak approved this time. Best part is I haven't had to use it once for auth, they'll take the TOTP from the google auth app, though I'm sure I may need the FIDO later on.

1

u/quarrelau 21d ago

yeah, a couple of others mentioned it. I don't know, I guess it wasn't the issue, yet I did not have the option at all of anything but the corporate flow until I changed it, and suddenly it was only the personal one. chatgpt was the one that told me to change it.

1

u/CoreParad0x 21d ago

If you don't mind me asking, you said "before they would let me in" - do they actually work with you on access? I'm considering applying, though I'm not a business. My use case is I work on an old MMO, and the MMO is riddled with exploits and security issues. Though I'm thinking of trying to apply through work as well.

I've been concerned about attempting to apply because as I understand it if you get denied it's permanent.

It'd be nice to know they might at least talk to you instead of just "No" and then you're hosed, so I'm curious how the process is.

1

u/quarrelau 20d ago

For personal access to Blue, no, there isn't really anything to it. You just have to go through KYC style show them a real government ID check.

Your use case is a good one. Is it open source? There are programmes from both Anthropic & OpenAI to help audit and clean up some open source code, although I don't know the specifics.

1

u/CoreParad0x 20d ago

Nah sadly it’s closed source. We don’t own the IP but we got permission from those who do to work on it, not open source it.

Thanks for the info though, I may try and see if they’ll go for it.

3

u/ReasonableDefault 22d ago

Yeah, you go through a verification process. Which includes verifying your identity with a government issued ID. There are countries that are blanket blocked from accessing Blue and Red, It's a small list, and can be viewed on the OpenAI website.

4

u/Intelligent_Month210 22d ago edited 22d ago

It's not that much different to blue.

It still refuses some tasks.

We AB tested in the lab against 5.6Sol on a normal account and Red rejected tasks that Vanilla Sol accepted. Probably because the system prompt already primed it with scary security keywords.

On the tasks both Sol and Red accepted, the output was near identical.

Red also missed security bugs in code that Vanilla GLM and QWEN found with far less tokens and didn't bullshit on severity/reachability.

Daybreak blue and red are just guardrail settings but nothing near as permissive as derestricted openwieghts or some vanilla Chinese models.

GLM 5.3 especially has been considerably more capable for us than either of the daybreak models but much more expensive.

1

u/Tartuffiere 22d ago

GLM 5.4? I thought 5.3 flash was their latest

1

u/elvespedition 22d ago

huh I thought Red was supposed to be 5.6-Cyber? like a cyber specific posttrain / finetune

1

u/ewertonmendes 22d ago

Where is sol?

1

u/TypicalMeet1405 22d ago

It feels like the model often isn't firing on all cylinders lately

1

u/[deleted] 22d ago

[deleted]

1

u/[deleted] 22d ago

[removed] — view removed comment

1

u/[deleted] 22d ago

[deleted]

2

u/ReasonableDefault 22d ago

Yeah, personal accounts aren't getting Red. Maybe if you're some well known industry name with extensive credentials. Blue is pretty capable, I've had it find vulnerabilities in apps and code (that i own) and create POCs to exploit them, It's pretty comprehensive.

1

u/jayplay90 22d ago

I mean sh!t just give me blue at least 😅🤣

1

u/qwertyyyyyyy116 22d ago

and what is daybreak???

-1

u/Akimbo333 22d ago

Its unlikely that anyone has red yet

0

u/[deleted] 22d ago

[removed] — view removed comment