OpenAI Rolls Out ‘Advanced’ Security Mode for At-Risk Accounts
New Security Option for High-Risk Users
OpenAI has launched Advanced Account Security, an optional feature designed to safeguard ChatGPT and Codex accounts that may be at higher risk of phishing attacks. With the rapid adoption of AI tools worldwide, the company is addressing the need for stronger protection for users deeply engaged with its services.
How Advanced Account Security Works
This enhanced mode requires users to set up two physical security keys or passkeys, eliminating the use of traditional passwords and standard recovery methods like email or SMS. Instead, recovery can only be accomplished with physical backup keys, passkeys, or recovery keys. OpenAI has collaborated with Yubico to provide discounted YubiKey bundles for those enabling this feature.
Key Features and Changes
- No support for password-only logins—only phishing-resistant authentication is allowed.
- Account recovery can only happen with backup or hardware keys, and OpenAI’s support team cannot reset accounts.
- Shorter sign-in sessions are enforced, and users receive instant alerts for all sign-ins, along with access to a dashboard showing active sessions.
- By default, conversations from accounts in Advanced Security mode are excluded from training OpenAI’s models.
Who Should Enable It?
This security mode is particularly recommended for professionals working with sensitive information—like journalists, dissidents, and elected officials—as well as members of OpenAI's Trusted Access for Cyber program, who must enable it by June 1 or show alternative strong authentication.
For more, read the original article by Lily Hay Newman at WIRED.