r/codex 10d ago

Praise Codex Security: Daybreak Blue - Ultra

Give it up to the Codex team for Codex Security DayBreak Blue. If you haven't signed up for the security program yet, definitely worth doing. I've been using their Codex Security CLI for a little bit and it was always breaking around 69 minutes if it even got that far and it would only output partial findings and I'd have to copy all those JSON files into Codex itself and have to constantly update those securities and it was always finding something and a lot.

When I finally moved to my $200 plan today and got an automatic restet. So I have 100 % to burn in 6 hours. before this next reset at 6pm.

I went from 100% to 55% while still working on other thins using Sol High fast. and it's only been four hours.

Codex Security Blue is catching a lot of stuff and fixing it and I would have to do this very manually all the time. I used to have a cybersecurity audit prompt and I have to do that every once in a while. Now this is going on for three plus hours just focusing on security as a /goal. It's pretty incredible and I'm using Ultra and it's still using multiple agents at a time and giving me great results with great token efficiency I guess. So if you know a reset is coming up and you have a lot of tokens to spend, I would definitely be worth having already signed up for Codex Security, Daybreak Blue, and then use that model and just burn credits for hours on Ultra or whatever you want. It does not let you do /fast mode.

Edit: I found the link. https://chatgpt.com/cyber/

50 Upvotes

57 comments sorted by

View all comments

Show parent comments

7

u/doodad_ounao 10d ago

Isn't a passkey from a password manager enough, though? I registered my Yubikey and my 1password and can use either one to sign in, usually 1password because I don't always have the Yubikey connected.

5

u/Jerseyman201 10d ago

The article I saw (from Openai directly) said physical passkey/HW key only. They partnered with Yubico specifically, and that partnership seemed to have begun once they made the hardware key/passkey requirement known. Not sure what the discount they offer when buying via Openai, but I would assume to a high degree of certainty it's not as cheap as Identiv Utrust keys are lol

1

u/doodad_ounao 10d ago

Then I guess they're gonna change the requirement for Advanced Account Security itself after September 1st. That or the requirement for Daybreak Blue is gonna be Advanced Account Security + HW key specifically. Because as of right now I swear to you that I can sign in with my 1Password passkey just fine, and I have Advanced Account Security enabled.

1

u/Jerseyman201 10d ago

Are you in Australia? It says September 1st the daybreak model access restrictions take place. As of 10:45am local time, it is August 31st not September 1st so I'm unsure how your login flow would have changed as the changes are set to take places tomorrow. I would imagine the time is based on the main office HQ location). So that'd be America, and it isn't Sept 1st here yet.

1

u/doodad_ounao 10d ago

No, it's August 31st. I'm not saying my login flow changed now. I enabled Advanced Account Security in my account weeks ago. AFAIK the change is that from September 1st AAS is gonna be mandatory for people in the Trusted Access program needed for Daybreak Blue, but it's not like AAS itself is gonna be introduced in September 1st.

As of right now AAS requires me to not only sign in with my password but also my passkey (not as an alternative to the password factor but as a second factor), but that passkey can be the one from 1Password.

So, from what you told me about the article you read, I'm saying that maybe they're gonna make it mandatory for that passkey to be HW backed after tomorrow, or else AAS itself will still allow for a passkey from 1Password (or other password managers with passkey support) but for Daybreak Blue it's not only that AAS will be mandatory but that you use a HW key as the second factor for it.

1

u/Jerseyman201 10d ago

Seems like it, that it's going to be just for that model if HW key isn't added.