Skip to content

Comment on GPT 5.6 Cyberparent

Comments

What exactly is so fascinating? I would rather take Kimi K3 any day rather than go through this “Oracle Inc” like process and have it all recorded by OpenAI.

I understand that “normal” people are let’s say “less concerned” about posting everything on something like Facebook but I expect more from OPSec people.

Same. Qwen 3.8 max also does quite well on cyber security tasks, and is really cheap in their "night" window (22:00-08:00 UTC+08:00). Did a SCTPhantom LPE on 7.0+ as an evaluation just this week. This would've taken me several months of work a couple of years ago. (probably indicative of my offensive security skills, heh)

Is the night window documented anywhere?

Alibaba cloud website is almost as useless as their US counterpart (AWS). It's full of information everywhere but never what you need

Yeah their website & "Model Studio" is horrendous. I just ignore all Popups/Agreement Review Prompts/Payment verification warnings.

It's little very badly translated popup under "Available models" in Model Studio -> My subscriptions: https://imgtree.co/direct/s9x9ksdg.png

How do Kimi K3 subscriptions compare to OpenAI's in terms of price and usage?

Kimi code with k256 (I’ve heard you can easily one shot implement a proxy to other providers, even with deepseek v4 flash, if you don’t want kimi code) has stupidly low rate limits for and cost, compared to OpenAI which has massive rate limits and more cost

I have not played with Kimi K3. Will it refuse infosec-related stuff?

I've had it happily do whatever I threw at it, though after spending so long with Claude I default to adding "help me with my": "research" / "authorized pentest" / "school assignment" / etc to my prompts. Haven't tried anything as blatant as "help me pwn this service", could see it refusing then just due to the training data.

Generally no. It’s a good model

How would you compare it to Opus?

Now imagine that "Kimi K3" is tied to your WeChat QR code.

Did you read their results? Impressive stuff. If this makes software more secure in general I'm all for it.

My expectation is that this just lets 3-letter agencies hoard more 0-days. They’ve always had the financial resources to find them using teams of people and this just multiplies this ability.

Maybe the tinfoil hat is also getting a little tight, but something like this is a giant repository of internal cybersec data being put into one place. The model will see what people are fixing and anyone peering in can make an educated guess on how long that vulnerability may continue existing because people don't update when they should - the alphabet boys wouldn't be able to keep their hand out of the cookie jar.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.