‹ BackHN Continuity

Thread

DeepSeek v4.1 Flash Is Now Our Best Hacking Model

177 points · 67 comments · talhof8

  1. TuxSH · · focus · HN ↗
    I find this - or perhaps the title - a bit surprising.

    I've benchmarked GLM 5.3 and DSv4.1-F on my fully-annotated decomp of the Nintendo 3DS's kernel, which I have a good mental understanding of, tasking them to find vulns and other bugs (in Max mode w/ subagents). GLM 5.3 founds almost all the vulns in 30min for $22, while DS only found one vuln for $2 in 40min.

    Perhaps DS works better where targets have low-hanging fruits than can be found fast?

    1. severino · · focus · HN ↗
      A little off-topic: where does one use those models such as GLM or DS for this kind of reverse engineering tasks? I think I read many of them refuse to help with tasks like those on their official platforms.
      1. TuxSH · · focus · HN ↗
        GLM 5.3 doesn't seem to refuse vuln research (which it classifies as "audit") and is good at it.

        Therefore you use for offensive cybersecurity tasks because Daybreak Red/Mythos is pure unobtainium for us mere plebians.

        DB Blue thankfully exists, but I suspect you risk a ban if you use it with codebases you neither own nor use

        Tl;dr because it's the only model at the level of 5.4~5.6 that doesn't refuse tasks nor risk your oai account getting banned

        For plain RE tasks Sol or Astra should work just fine (I think)

      2. SSLy · · focus · HN ↗
        GLM-5.3; well, the flash variant at least; you just ask what to do and it complies with no objections :^]
      3. drdebug · · focus · HN ↗
        You can run deepseek-v4.1-flash on a local server with 4xH200@141GB for around 180K EUR. It can serve more than one user so it can be a good investment for a company, especially if you need your data to stay local (although I would advise do go a step up and populate with 8xH200 to serve many more users, ~300K EUR). You can run whatever test you want and you won't be limited by a front-end that pre-filters your requests.
      4. trollbridge · · focus · HN ↗
        I use DS straight off of DeepSeek's API.

        It was very helpful in the aftermath of a client whose WordPress got stuffed up and analysing when it happened, how it happened, and what the entry point was. The American frontier models refused to help because, well, they just refuse to help with that kind of thing.

      5. samvher · · focus · HN ↗
        I've been testing these models with fireworks.ai

        They provide serverless access, and if you use fireconnect it's also easy to hook the models up to e.g. codex which allows for fairly clean comparisons

        I think they provide the bare model (no filter) but I might be wrong, haven't tried using it for security research yet

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.