Why Kimi? because K3 is the only frontier model I can have a serious conversation with about my product's security.
(I did apply for OpenAi's Cyber Pilot but got no response)
Why Kimi? because K3 is the only frontier model I can have a serious conversation with about my product's security.
(I did apply for OpenAi's Cyber Pilot but got no response)
This is highly problematic.
But after I fixed it and tried to talk to Claude again Claude stonewalled me like it assumed I was trying to introduce a hole…
Same experience with Anthropic's. I applied for my employer, and.. 0 response.
I can't say it has helped much, though. Fable is still completely useless for securing code. Opus does an OK job, though.
Fable smacked me for asking it to design a secure app without obvious security flaws and to double check it wasn’t using libraries with known security problems.
(Grade 3 AI which can hack both previous tiers is exclusively sold to the highest bidder.)
It's also not a very good marketing strategy, secure software and quality also goes in pair and it just makes me doubt about the output of Fable/Sol
OpenAi (and Anthropic) have no incentive to allow security access to individuals. I'm not a deep-pocket org or influential gov agency. Allowing individuals increases the risk of bad press (what if I do something naughty and talk about it?) so best to ignore us.
This is wrong IMO. You should have a serious conversation about your products security with someone who is actually trained on that subject. LLMs are useless if you don't already know more about the thing than the LLM, or if you don't care too much about the outcome (internal tools etc.)
You can easily see this if you are using LLMs in a field you are an expert in
My point and frustration is that gatekeeping in the name of Security makes the Chinese models actually better at security than USA models.
How did you read: "K3 is the only FRONTIER MODEL I can have a serious conversation with about my product's security" and infer that there isn't anyone with training also in the loop?
Did you seriously think: "they use an LLM so it's impossible they use a human with cyber experience; it's not like they could be using both (as would be expected when securing code). I'll help them out by using an oversimplified explanation suitable for a small child yet completely missing the OPs meaning. "?