Hacker News new | ask | show | jobs
by dangelosaurus 1 day ago
Thanks! You've run into a real limitation: the CLI doesn't bypass the model's cybersecurity guardrails. If GPT-5.6 Sol finds a vulnerability but refuses to explain it, switching from the Codex app to the CLI won't automatically fix that.

For authorized defensive work, Trusted Access for Cyber (TAC1/Daybreak) can reduce refusals depending on the model and the account or organization where access is provisioned. It isn't a blanket bypass.

If you're an open-source maintainer, you can apply for conditional Codex Security access here:

https://openai.com/form/codex-for-oss/

For enterprise teams, the public Daybreak onboarding guide is here:

https://help.openai.com/en/articles/20001261-enterprise-dayb...

If you have an example of "found a vulnerability but won't tell me what it is," I'd love to take a look too. You can send it to use with /feedback (or message me).

3 comments

> If you're an open-source maintainer, you can apply for conditional Codex Security access here:

> https://openai.com/form/codex-for-oss/

Hey, Lead maintainer of vim here. Applied twice already never heard anything back. This is a frustrating experience!

Please email me and I will help fix this.
>> For authorized defensive work, Trusted Access for Cyber (TAC1/Daybreak) can reduce refusals

Or perhaps a better option is to use something like Kimi K3 and cancel the GPT subscription altogether.

Or try Grok, 4.5 seems pretty capable, should be close to K3 in many coding tasks. I use it for code review of what other "stronger" models shit out (like Sol) and it constantly finds even pretty big bugs or just not robust enough solutions (Sol tends to overengineer, yes, but I'm not so sure it overengineers the right parts, so far my experience woth it has been mid. Except it understanding my drawings and collages and it being capable of far better frontend/design dev than 5.4 or even 5.5 was).
Sounds like that's the only solution. I'm so sick of this safety nonsense I was going to switch from Anthropic to OpenAI because of it. I'm so disappointed to see it's just more of the same.

Model finds a vulnerability in your code but "refuses" to tell you. Words can hardly express the sheer absurdity of it.

It’s like they want to squeeze more money from you with the cyber crap…reminds me of all the DRM stuff around music distribution…
> GPT-5.6 Sol finds a vulnerability but refuses to explain it

I think it would be a good practice to refund the session cost in that case. Otherwise a customer just spent some money in order to get exactly nothing.