惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

爱范儿
爱范儿
Microsoft Azure Blog
Microsoft Azure Blog
G
Google Developers Blog
宝玉的分享
宝玉的分享
V
V2EX
MongoDB | Blog
MongoDB | Blog
S
SegmentFault 最新的问题
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Microsoft Security Blog
Microsoft Security Blog
博客园 - 聂微东
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
IT之家
IT之家
Martin Fowler
Martin Fowler
大猫的无限游戏
大猫的无限游戏
Recent Announcements
Recent Announcements
人人都是产品经理
人人都是产品经理
博客园 - 司徒正美
美团技术团队
F
Fortinet All Blogs
N
Netflix TechBlog - Medium
Hugging Face - Blog
Hugging Face - Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
罗磊的独立博客
B
Blog RSS Feed

Yubico

Secure it Forward Spotlight: Cybersecurity as a key foundation for civic infrastructure Yubico expands OpenAI partnership to new countries as hardware-backed passkey mandate begins for Trusted Access for Cyber program Beyond overload: Yubico's measured approach to AI adoption Code and connections: Inside Yubico’s YubiKey 5.8 Hackathon Leading Yubico forward: Q2 reflections and securing the AI frontier What the European Central Bank’s October 2026 AI cyber mandate means for bank identity security The ‘Air-Gap Conundrum’: When Password Managers Meet the Data Center Floor The Defense Industrial Base Has a New #1 Cybersecurity Priority: Phishing-Resistant MFA RIP SMS: Microsoft transitioning to passkeys as default authentication method for Entra ID Beyond the login: Top 3 things developers need to know about YubiKey 5.8 Works with YubiKey Spotlight: Translating YubiKey logistics into enterprise cyber resilience with EgoMind’s Appterix Google Play Services adds support for NFC-enabled FIDO2 security keys: How Yubico makes Android passkey authentication seamless Post-quantum cryptography is now a federal mandate: Here’s what it means and what your agency should do now Salesforce enforces MFA for all employee logins: Here’s what you need to know Secure it Forward Spotlight: Cyber defenders as a force for resilience New Executive Order on AI: Identity as a critical foundation for trusted AI YubiKey 5 FIPS Series and YubiHSM 2 FIPS are now FIPS 140-3 validated: What it means for high assurance security Secure It Forward Spotlight: Securing independent journalism with Radio Free Europe / Radio Liberty The passkey spectrum: Importance of user choice in digital security journeys OpenAI’s Advanced Account Security program: Top 5 things Codex users need to know New to OpenAI’s Advanced Account Security program? Here’s how to add your YubiKey to ChatGPT accounts Leading Yubico forward: Q1 reflections and securing the AI frontier Building a safer AI journey: How to add your YubiKey to ChatGPT accounts OpenAI partners with Yubico: What it means for the future of AI-based workflows and the role of the human Works with YubiKey Spotlight: Securing the AI frontier and high-assurance infrastructure Yubico’s commitment to securing the future of digital identities: Reflecting on RSAC 2026 YubiKey as a Service expands to Ping Identity with pre-configured security keys Securing agentic AI: Why automation still needs human oversight Yubico officially lands in Singapore: Opening our third global headquarters Welcome to YubiNation Partners: Reimagining the Future of Channel Partnership to Secure Identity at Scale
OpenAI mandates hardware-backed passkeys for Trusted Acce...
Jerrod Chong · 2026-07-10 · via Yubico

The rapid advancement of AI is changing the global cybersecurity landscape. As these technologies become more powerful, safeguarding access to them is increasingly critical — particularly for the security researchers and defenders working to identify vulnerabilities, strengthen software and improve cyber resilience. People need advanced account protection that can withstand modern phishing and social engineering attacks, helping ensure state-of-the-art AI capabilities remain in the hands of trusted users. 

Today’s announcement from OpenAI sets a new industry standard: starting September 1, all individual members of Trusted Access for Cyber (TAC) must enable Advanced Account Security using a hardware-backed passkey to retain access to frontier cyber models. Additionally, OpenAI is tightening access restrictions for high-risk entities and jurisdictions.

At Yubico, we believe the future of AI security depends heavily on identity and authenticator assurance, not just model safety. When the stakes are this high, organizations can no longer rely on software-based controls or legacy multi-factor authentication (MFA), both of which are easily bypassed or intercepted. True security requires a phishing-resistant, hardware-backed root of trust built on credentials that cannot be copied or synced.

Protecting TAC with hardware-backed passkeys makes accounts significantly more difficult and costly for threat actors to exploit at scale. By dramatically raising the barrier to entry, this approach disrupts the criminal ecosystem that relies on creating, validating, and reselling compromised accounts for downstream abuse.

Securing your ChatGPT account with YubiKeys

Moving to hardware-backed protection is a seamless process for TAC members aligning with the new mandate. Through OpenAI’s Advanced Account Security program, security keys provide a higher-assurance environment by deliberately disabling weaker fallback methods. This partnership allows you to replicate the identical security posture that OpenAI uses internally to safeguard its own infrastructure and employees. To facilitate this transition, a custom 2-pack of YubiKeys is available to existing account holders at preferred pricing.

  • YubiKey C NFC – OpenAI: Perfect for the modern mobile workforce. Authenticate instantly with a simple tap against your phone or tablet.
  • YubiKey C Nano – OpenAI: Designed for maximum convenience. Plug it into your laptop’s USB-C port and leave it there for effortless, continuous protection.

Once enrolled, users experience the gold standard of phishing-resistant security through a fast, entirely passwordless experience. To secure your ChatGPT accounts with YubiKeys today, visitchatgpt.com/advanced-account-security or read the full partnership details here.