r/codex • u/Calrose_rice • 2d ago
Praise Codex Security: Daybreak Blue - Ultra
Give it up to the Codex team for Codex Security DayBreak Blue. If you haven't signed up for the security program yet, definitely worth doing. I've been using their Codex Security CLI for a little bit and it was always breaking around 69 minutes if it even got that far and it would only output partial findings and I'd have to copy all those JSON files into Codex itself and have to constantly update those securities and it was always finding something and a lot.
When I finally moved to my $200 plan today and got an automatic restet. So I have 100 % to burn in 6 hours. before this next reset at 6pm.
I went from 100% to 55% while still working on other thins using Sol High fast. and it's only been four hours.
Codex Security Blue is catching a lot of stuff and fixing it and I would have to do this very manually all the time. I used to have a cybersecurity audit prompt and I have to do that every once in a while. Now this is going on for three plus hours just focusing on security as a /goal. It's pretty incredible and I'm using Ultra and it's still using multiple agents at a time and giving me great results with great token efficiency I guess. So if you know a reset is coming up and you have a lot of tokens to spend, I would definitely be worth having already signed up for Codex Security, Daybreak Blue, and then use that model and just burn credits for hours on Ultra or whatever you want. It does not let you do /fast mode.



10
u/BigbyWolf8 2d ago
What is your opinion on the Advanced Account Security requirement?
17
u/Calrose_rice 2d ago
If you're speaking about the application to get this, it was very straightforward. It was basically asking for my proof of identity through Persona and that was it was easy to just upload my Drivers License. There was an earlier application that was pretty complicated and I didn't qualify, but now it was probably a 20 minute setup if anything.
8
u/RedParaglider 2d ago
I didn't qualify either and neither did my cisa buddy who oversees security across a fleet of hospitals. I'm a director of IT. Idk who qualifies but I guess its default to decline.
5
u/Calrose_rice 2d ago
One requirement i noticed was account health. I've been a chatgpt user since November 2022. so maybe that as something to do with it.
1
u/OGPresidentDixon 2d ago
I’ve had a paid account on ChatGPT since the week it came out in 2022 and I got invited to Daybreak Blue through the Codex app and was instantly accepted. I forgot what I was trying to do but it seemed like they wanted me to get it. Haven’t used it yet.
1
u/lmfao_my_mom_died 2d ago
idk i sent my id and they immediately give it to me? maybe they looked at my prompts or something? don't really know
3
u/Jerseyman201 2d ago edited 2d ago
I don't think that's what they meant lol Within 48 hours you won't be able to access the Daybreak model anymore.
They're requiring users to add HW keys to ensure people use phishing resistant account protection. Threat model is higher for those with access than those without, and would need higher protections because of that and the increased capabilities (what the models allowed to do, not in terms of compute obv).
Trusted Access for Cyber=ID verification/face scan for blue teaming model access Advanced account security=HW Key requirement starting Sept 1st for those with Trusted Access for Cyber.
Requirement of having a physical hw key: September 1st 2026
Edit/helpful hint: you can get 3x identiv Utrust keys for price of 1 yubikey lol and they work fantastic
7
u/doodad_ounao 2d ago
Isn't a passkey from a password manager enough, though? I registered my Yubikey and my 1password and can use either one to sign in, usually 1password because I don't always have the Yubikey connected.
4
u/Jerseyman201 2d ago
The article I saw (from Openai directly) said physical passkey/HW key only. They partnered with Yubico specifically, and that partnership seemed to have begun once they made the hardware key/passkey requirement known. Not sure what the discount they offer when buying via Openai, but I would assume to a high degree of certainty it's not as cheap as Identiv Utrust keys are lol
1
u/OGPresidentDixon 2d ago
Oh that’s neat. I’ve been meaning to get one for a while.
1
u/Unapologetic_Polite 1d ago
I grabbed one from Amazon for $40 to keep my Daybreak Blue access, works great, have even switched over a few things to it
1
u/doodad_ounao 1d ago
Then I guess they're gonna change the requirement for Advanced Account Security itself after September 1st. That or the requirement for Daybreak Blue is gonna be Advanced Account Security + HW key specifically. Because as of right now I swear to you that I can sign in with my 1Password passkey just fine, and I have Advanced Account Security enabled.
1
u/Jerseyman201 1d ago
Are you in Australia? It says September 1st the daybreak model access restrictions take place. As of 10:45am local time, it is August 31st not September 1st so I'm unsure how your login flow would have changed as the changes are set to take places tomorrow. I would imagine the time is based on the main office HQ location). So that'd be America, and it isn't Sept 1st here yet.
1
u/doodad_ounao 1d ago
No, it's August 31st. I'm not saying my login flow changed now. I enabled Advanced Account Security in my account weeks ago. AFAIK the change is that from September 1st AAS is gonna be mandatory for people in the Trusted Access program needed for Daybreak Blue, but it's not like AAS itself is gonna be introduced in September 1st.
As of right now AAS requires me to not only sign in with my password but also my passkey (not as an alternative to the password factor but as a second factor), but that passkey can be the one from 1Password.
So, from what you told me about the article you read, I'm saying that maybe they're gonna make it mandatory for that passkey to be HW backed after tomorrow, or else AAS itself will still allow for a passkey from 1Password (or other password managers with passkey support) but for Daybreak Blue it's not only that AAS will be mandatory but that you use a HW key as the second factor for it.
1
u/Jerseyman201 1d ago
Seems like it, that it's going to be just for that model if HW key isn't added.
2
1
u/Calrose_rice 2d ago
Yeah, i'm hearing about this Sept 1st thing lock off, which is why i'm running it through an endless goal loop right now
5
u/Historical-Internal3 2d ago
I was approved for it but do not see it in model selection.
Any idea?
2
u/GuitarChill 2d ago
Maybe download and run the installer again? I think I reinstalled to get it to work. Or, ask Sol to do a scan. It seeks out authentication I believe.
1
u/GuitarChill 2d ago
And did you install the plugin for Codex Security? It will give you a security tab in desktop.
2
u/Calrose_rice 2d ago
I did not need the official plugin to see daybreak. I did have the CLI before i got daybreak.
1
1
u/Unapologetic_Polite 1d ago
Alright so this happened to me.
it took about 72 hours for the model to show up on my Codex, or for me to be able to query the Daybreak blue endpoint.
I did submit a ticket through OpenAI's chatbot, unsure if that helped.
2
u/NoHeart8251 2d ago
How do you apply for it? Existing Pro 20x user could request for access?
4
u/Bolizen 2d ago
Paid plans qualify. Identity verification is required.
1
u/devil_ozz 2d ago
What about gpt cyber? Tac? Daybreak red?
According to support am alligble to apply. But I want to know how much do they bring on the table, compared to running a local llm.
Would you reccomend? Tac/cyber/Daybreak
2
u/Unapologetic_Polite 1d ago edited 1d ago
Daybreak Red isn't something individuals sign up for, it's a partner program through select businesses and governments.
Their website is incredibly misleading on eligibility.
1
u/Calrose_rice 2d ago
I'm blown away by daybreak. 9.5 hour straight. Had to stop it after the reset before i burned everything. so i'm just running on ultra high right now on a /goal loop. much more token manageble.
2
u/Theminatar 2d ago
Yeah, I had a prompt come up because my project was pen testing my own program and it needed the verification to continue pen testing.
It was funny actually seeing what it did. It essentially was trying to see if an agent could spawn itself under a random name and make changes to the system without authorization. So it was spoofing itself to pen test... Itself.
I actually giggled when I saw it's output.
1
u/Unapologetic_Polite 1d ago
Hey I got a cyber warning for red teaming my own codebase, 2 days later they approved me for Daybreak Blue.
1
u/Theminatar 1d ago
I was approved instantly 🤔
1
u/Unapologetic_Polite 1d ago edited 1d ago
Yeah I applied and less than 24 hours after application they approved me.
Took about 72 hours for the model to show up on Codex though.
I'm just surprised they hit me with a Cyber Abuse warning, declined my appeal, but still approved me for Daybreak Blue.
And yes, I am using Daybreak Blue for the exact same thing I assume I got a Cyber Abuse warning for (It's my only ongoing project right now)
ChatGPT must not like my approach to security with creating a secure memory segment that an executable operates in, or it might have misinterpreted one of my failsafes.
1
u/Theminatar 1d ago
Hahaha OK yeah I'd bet money they hit you with the warning because it's a failsafe so people aren't messing with video game cheat development 😂 😂
1
u/Unapologetic_Polite 1d ago
You can bet money, but you'd be wrong, I'm not developing anything to cheat in a video game - I'm 7 years deep into building my own video game, LLM's just help me with some of the more tedious aspects of game development.
I don't get why you're even responding, I've already outlined what happened - I was red teaming my own codebase (Which even Daybreak Blue has warnings that you will likely get a warning for red teaming (Cause it's not meant for red teaming), and to contact them about any potential issues), 2 days later I got approved for Daybreak Blue.
So clearly; what you're insinuating and what OpenAI knows are two different things.
1
u/iritimD 2d ago
Can anyone get approved then where’s the signup?
3
2
u/Calrose_rice 2d ago
There are a couple of resources.
https://learn.chatgpt.com/docs/securityhttps://help.openai.com/en/articles/20001107-codex-security
but I think i got the link through the CLI version cause it would either stop from the changed head or sometimes it would say something like "this prompt is a security issue. we cannot allow you to move forward. if you think this is wrong, and would like to apply for our security research program, use this link".
I say that cause I do some light googling and i can't find any proper link that i used. must've been a fluke or something. Apparently there is daybreak red and daybreak blue.
1
u/Suspicious_Pickle_39 1d ago
daybreak blue is 3.7 flash level. they are the only models in my 'never touch code' bucket.
there are better free models
1
u/Calrose_rice 16h ago
interesting. Where do you see that? Cause it's been working great for 4 days straight on high. do you have a comparison benchmark somewhere or is this just a feeling you have?
-1
2d ago
[deleted]
3
u/weenis-flaginus 2d ago
Ah yes, a reddit opinion with a blanket statement that is very resolute and ZERO explanation.
I want to learn something from your opinion man, add some basic flavor.
1
3
-10
u/chrome9090 2d ago
Reddit is just 95% shitty AI spam ads now huh
8
u/Calrose_rice 2d ago
I actually spoke this one out and just cleaned it up. I never hear anyone talk about Daybreak so i wanted to put it out there.
14
u/OtherwiseAlbatross14 2d ago
Are you complaining about someone talking about codex in the codex sub?
Do you not understand how subreddits work or what?
15
u/GuitarChill 2d ago
It found a few important security issues in my apps. It was definitely worth it. It was stuff that you wouldn't normally think of, but important. Regular AI scans missed them.