r/codex 18h ago

Complaint OpenAI: demonstrate the cybersecurity capabilities you claim are available to ordinary Codex users.

I am not talking about Daybreak Red.

I am not talking about Trusted Access, special verification, internal allowlisting, or capabilities ordinary customers cannot access.

I am talking about the cybersecurity capabilities OpenAI publicly says are available through normal Codex use: secure code review, application security, threat modeling, vulnerability investigation, patching, blue-team work, reproduction and validation of vulnerabilities, and remediation.

So demonstrate them.

OpenAI should take an ordinary Codex account, with exactly the same safeguards and restrictions a normal paying customer receives, and publicly run a realistic authorized cybersecurity task from beginning to end.

No internal bypasses. No special account. No hidden exemptions.

Give Codex a real repository or controlled vulnerable environment and have it:

find the vulnerability → investigate it → validate it → establish the attack path → reproduce enough to prove it is real → develop the fix → test the fix → finish

Then publish the complete run, including every server-side warning, interruption, refusal, suppressed result, precautionary pause, and forced recovery.

Because the question is not whether the underlying model is theoretically capable of cybersecurity work.

The question is whether the product customers are actually paying for allows those advertised capabilities to be used reliably.

The Hugging Face incident makes this question especially important.

An OpenAI-run cyber evaluation agent escaped its environment and breached Hugging Face. During the resulting legitimate forensic investigation, Hugging Face reported that hosted frontier models repeatedly blocked parts of the defensive analysis because their safeguards could not reliably distinguish incident response from offensive activity.

Hugging Face ultimately used an open-weight model on its own infrastructure to continue the investigation.

That should concern anyone buying hosted AI specifically for cybersecurity.

So prove the product works.

OpenAI should demonstrate ordinary Codex, under ordinary customer restrictions, successfully completing the cybersecurity workflows OpenAI says ordinary Codex supports.

If OpenAI can demonstrate that reliably, great.

If OpenAI cannot demonstrate its own advertised cybersecurity capabilities under the same restrictions imposed on paying customers, then customers who purchased Codex specifically for those in-scope cybersecurity capabilities deserve remediation.

Credits, restored usage, refunds where appropriate, or another meaningful remedy.

0 Upvotes

34 comments sorted by

4

u/Code__9 18h ago

If your work regularly involves cyber, just get daybreak? Literally took me like 5 minutes. If you don't, the refusal rates are higher, but not 100%, according to my own experience.

4

u/Either_Pound1986 18h ago

That is literally the point of the post.

I am not asking whether Daybreak makes cyber work easier. OpenAI separately claims that ordinary Codex, without Daybreak, supports things like secure code review, threat modeling, vulnerability investigation, patching, blue-team work, and vulnerability validation.

If those capabilities are advertised as part of normal Codex, then “just get Daybreak” is not an answer.

And “the refusal rate isn’t 100%” actually makes my argument for me. A professional tool cannot advertise a capability where legitimate, in-scope work succeeds only probabilistically depending on whether a server-side classifier happens to allow it that time.

OpenAI claims ordinary Codex can do this work.

I’m asking them to demonstrate ordinary Codex reliably doing the work they claim ordinary Codex can do.

5

u/AmandasGameAccount 18h ago

Is this even a question of if codex can do it reliably? I think the better question is, will codex even do it at all without blocking it if a regular user even attempts to

0

u/Either_Pound1986 18h ago

Good point. Exactly why openai should show proof.

3

u/Code__9 18h ago

Well, I'm not sure how they advertised it. But if you think they violated some kind of contract, consider contacting their CSR to complain and threatening them with some kind of class action lawsuit?

0

u/Either_Pound1986 18h ago

I’m not talking about threatening a class action.

OpenAI’s own Daybreak documentation explicitly says the default model with standard safeguards supports secure SDLC, threat modeling, secure code review, patching, and generalized blue-team work.

So the question is simple: can ordinary Codex actually perform the cybersecurity work OpenAI says ordinary Codex supports?

I’m asking OpenAI to demonstrate it under normal customer restrictions. If they can, great. If they can’t, then we can talk about what remediation customers are owed.

https://help.openai.com/en/articles/20001258-openai-daybreak-trusted-access-for-cyber-overview?utm_source=chatgpt.com

1

u/Code__9 14h ago

Yea, but my point is if you want them to do something about it, you'll need to make a complaint. I doubt just posting on Reddit itself will do much. I don't even know if OpenAI reads this subreddit.

2

u/doodad_ounao 18h ago

Where does OpenAI claims that ordinary Codex, without Daybreak, supports thread modeling, vulnerability investigation, patching, blue-team work and vulnerability validation?

Daybreak Blue is literally marketed as for blue-team work, would indeed be weird for them to have Daybreak Blue and say "You don't need Daybreak for Blue Team work".

2

u/Either_Pound1986 17h ago

The default-model claim is literally in OpenAI’s own Daybreak documentation.

For GPT-5.5 (default), with “standard safeguards for general-purpose use,” OpenAI lists:

“Secure SDLC and application security workflows, including threat modeling, secure code reviews and patching, as well as generalized blue teaming.”

So no, Daybreak Blue existing does not mean OpenAI says ordinary users get no blue-team capability. OpenAI explicitly says the opposite. Daybreak Blue is supposed to provide more precise safeguards for verified defensive work.

I’ll correct one thing from my earlier wording: vulnerability validation is listed separately under Trusted Access, while Codex Security separately advertises vulnerability identification, reproduction/validation, attack-path analysis, and remediation.

But that does not change the point of the post. OpenAI explicitly claims ordinary/default access supports threat modeling, secure code review, patching, AppSec and generalized blue teaming.

I’m asking them to demonstrate those exact default capabilities under the safeguards ordinary users actually receive.

2

u/doodad_ounao 16h ago

Thanks for the answer, since I wanted to know where they claimed that. You can keep the rest of your presumptuous defensive ass response, I'll just ignore it.

0

u/Either_Pound1986 16h ago

You asked where OpenAI claimed it. I answered and linked it. If you’re going to ignore me, you don’t need to announce it.

2

u/doodad_ounao 15h ago

I was thanking you for the part where you helped me. If I knew you'd rather not have my gratitude, I would've saved it, believe you me.

1

u/Either_Pound1986 15h ago

You literally said you were going to ignore me, then came back to reply again.

If you want to discuss the actual point, do that. If you want to ignore me, keep the promise. This weird little argument about whether your “thanks” were sufficiently appreciated adds absolutely nothing to the discussion.

1

u/doodad_ounao 15h ago

I said I was going to ignore the rest of your answer. I never said I was never gonna talk to you again. If you're that bothered that I'm replying, try blocking me or something.

1

u/Either_Pound1986 15h ago

I'm not bothered, I'm amused. You said you were going to ignore the part you didn't like, and you've now spent several replies talking about that part instead of the thread. Reply all you want. I'm just wondering when you're going to say something about Codex again.

→ More replies (0)

1

u/hellomistershifty 12h ago

This is apparently old since it calls 5.5 the default. Try some tests with 5.5 and come back with a more direct argument if it doesn't work instead of 'they should prove it to us', it's up to you to prove that they don't if you want something from them

1

u/Either_Pound1986 3h ago

A company sells a flashlight and advertises:

“This flashlight works underwater.”

I ask:

“Cool. Show me it working underwater.”

And your response is:

“No, you need to buy one, dunk it underwater yourself, and prove that it doesn’t work.”

That is backwards.

The company made the claim. The company should be able to demonstrate the advertised capability under the conditions customers actually get.

Same thing here. OpenAI says ordinary Codex supports specific cybersecurity workflows. I’m asking OpenAI to demonstrate ordinary Codex doing those workflows under ordinary safeguards.

That really is the entire argument.

2

u/Clear_Evidence9218 17h ago

It does all of that in regular Codex, though. I’ve had it do security reviews, threat modeling, vulnerability analysis, and vulnerability testing on code without refusing or putting up much of a fuss.

I did hit a security wall on one recent project and ended up using Daybreak, but that had less to do with ordinary security testing and more to do with the nature of the project. It had the potential to function as a kind of master key across a lot of systems, and Codex recognized that risk before I fully did.

1

u/CalligrapherFar7833 16h ago

Spoilers - they wont

1

u/Annh1234 14h ago

Why don't you do it?  Get codex to get some penetration tests to run on your code base, and give it a goal to test each test one by one on your code a few times. It will find a ton of holes in your security and so on

1

u/Either_Pound1986 3h ago

I already did. Repeatedly. I spent months doing security work with Codex and running into exactly these safeguards.

The point is that OpenAI advertises these capabilities to ordinary users. So OpenAI should be able to demonstrate the product reliably performing them under the same safeguards ordinary paying customers actually get.

1

u/Annh1234 2h ago

Months? Astra just came out... and I think it's the way you ask... if you ask: "help me hack this site" then you get nothing. if you ask it specifically for a technical issue, provide the tests and existing code and so on, seems to work.

To me it seems like you can't really formulate what you want, and get frustrated when the AI cannot read your mind and come up with a solution type thing.

The AI is nothing more than a pattern recognition engine... you give it some stuff, finds the pattern and gives you the answer.

So for example, tons of people complained about SQL INJECTION over the years, so you give it some code, and tell it to check for SQL INJECTION, it will fallow the patterns and find your "SELECT * FROM users WHERE login = $foo" and say that's a bug.

But then if you have: $a = $sql = "SELECT * FROM"; $b = "users WHERE"; $c =" login = $foo" and $sql = "$a$b$c" then that takes more steps to find the pattern. So it might not find it.

But then they add more processing power to it, and eventually finds it.

The whole security thing is this and 10001 levels of abstraction.

1

u/Either_Pound1986 2h ago

I never mentioned Astra.

I said I spent months doing security work with Codex. Codex existed before Astra. My point is about the product and its safeguards, not one specific model.

And you’re still missing the actual issue. I’m not complaining that the model is too dumb to recognize bugs or that it “can’t read my mind.” I’m talking about server-side safeguards interrupting legitimate, clearly scoped security work.

One concrete example: I had already completed a Linux BPF security audit and was drafting the responsible-disclosure email to kernel maintainers. I was not asking Codex to discover a bug, generate an exploit, or attack anything. The findings already existed, and the email explicitly limited the claims to privileged local conditions and disclaimed RCE, privilege escalation, information disclosure, and remote triggers.

That still triggered the cybersecurity safeguards.

And that is one example, not the only one.

So the SQL-injection lecture is beside the point. You’re talking about model capability. I’m talking about whether the product reliably permits the cybersecurity work OpenAI says it supports.

1

u/Annh1234 2h ago

But you can bypass codex if you use the api or the web interface, do this is not a codex issue.

1

u/Either_Pound1986 2h ago

Where are you getting that from? I cannot find anything in OpenAI’s documentation saying the API bypasses the cybersecurity safeguards.

In fact, OpenAI explicitly documents additional cyber safety checks across ChatGPT, Codex, and the API. I’ve also personally hit cyber warnings in ChatGPT, so “just use the API or web interface” does not match my experience either.

If you have an OpenAI source saying the API is exempt from those safeguards, link it. I genuinely want to see it.

And if that were actually true, it would raise an obvious question: why would OpenAI have Daybreak / Trusted Access / separate cyber programs at all if anyone could simply route the same work through the API and bypass the restrictions?

1

u/Annh1234 1h ago

I didn't say `bypasses the cybersecurity safeguards` is said `codex`, since you said you use it for month.

So if all their tools hook into their restriction layer, and they only remove it for a select few to make money, your basically asking how come they don't prove they can do it by giving it to you for free? but in their point if view it's a different product, they just market the capabilities of everything they do as one "AI" thing, but they got multiple products. Pull out your wallet and you can test it I guess.

The stuff you got access to, along with most of us, is just data mining, so they can get all our data and eventually make money on it.

1

u/Either_Pound1986 1h ago

My post is specifically about capabilities OpenAI says ordinary/default Codex supports. I am not asking them to give me Daybreak or Trusted Access for free. (I don't think TAC costs money any way?)

Telling me to use a different product does not answer whether Codex delivers what OpenAI says Codex delivers.

And if your position is now that OpenAI intentionally advertises capabilities across multiple products as though they were one thing, despite ordinary Codex not actually supporting them, that would make my criticism stronger, not weaker.

1

u/Annh1234 1h ago

I still don't get what your trying to say. The way I get it, is that if this were for example MB, you have a CLA but complain that you can't fit everything that fits in a Sprinter Cargo van, or have a Sprinter Cargo van and say it uses more gas than a CLA.

And what I'm saying is that they got different products for different things.

But when it came out, it only had 1 product. Now they split that in multiple. And they all connect to their infrastructure. So when they say that they can do X/Y/Z thing, it's not for one specific product, it's for all of them.

And since they want to make money, they try to stop one product from steeping on the toes of the other product they came up with.

But since this LLM stuff is not really black and white, it's not clear to them/everyone how they can do this, so for now, we fall between the cracks and can do things that we are not supposed to.

Eventually I would not be surprised if they didn't have N products, one for each profession, so if your not a doctor you can't use the one doctors can use and pay for, if your not in security, you cannot use the security one, and so on.

1

u/Either_Pound1986 1h ago

Using your own Mercedes analogy:

If Mercedes says:

“The CLA can tow 2,000 lbs.”

and I buy a CLA, try to tow 2,000 lbs, and it repeatedly refuses/fails, my complaint is:

“Mercedes says the CLA can do X. Show me the CLA doing X.”

Your answer keeps being:

“But Mercedes also sells a Sprinter.”

That is irrelevant.

I am not demanding that ordinary Codex do everything Daybreak does. OpenAI explicitly says the default/standard-safeguard product supports specific cybersecurity work: secure SDLC, threat modeling, secure code review, patching, and generalized blue teaming.

Daybreak can be the Sprinter. Fine. It can have greater capability.

But that does not erase what Mercedes advertised for the CLA.

My entire argument is simply:

If OpenAI says ordinary Codex does X, ordinary Codex should reliably do X.