Some irony: I subscribe to Claude and Codex (20x plans), and now Kimi.

Why Kimi? because K3 is the only frontier model I can have a serious conversation with about my product's security.

(I did apply for OpenAi's Cyber Pilot but got no response)

The product strategy of 'consumer-grade' AI making deliberately insecure software, and then selling you limited access to the model that can fix it (if they think you deserve to pay them) is just diabolical.

(Grade 3 AI which can hack both previous tiers is exclusively sold to the highest bidder.)

I don't think it's nefarious, but the end result leads to a pretty frustrating experience by anybody needing actual security work. (and without the organizational deep pockets to obtain SOC 2 attestation)

> AI making deliberately insecure software, and then selling you limited access to the model that can fix it (if they think you deserve to pay them) is just diabolical.

It's also not a very good marketing strategy, secure software and quality also goes in pair and it just makes me doubt about the output of Fable/Sol

[flagged]

> K3 is the only frontier model I can have a serious conversation with about my product's security.

This is wrong IMO. You should have a serious conversation about your products security with someone who is actually trained on that subject. LLMs are useless if you don't already know more about the thing than the LLM, or if you don't care too much about the outcome (internal tools etc.)

This has been the prevailing advice all along, and yet we have security vulnerabilities everywhere that LLMs are good at spotting and exploiting. I think we need more options on the menu.

I think I like this perspective because it points to where regulation might be more usefully applied than “the oracle must be prevented from answering certain question” and more like, “if you handle PII or provide services as a defense contractor, you may not take security advice from an oracle”