FB pixel

OpenAI rolls out passkeys for ChatGPT, partners with Yubico

FIDO2-based passkeys and YubiKeys target phishing and account takeover risks
Categories Access Control  |  Biometrics News  |  Trade Notes
OpenAI rolls out passkeys for ChatGPT, partners with Yubico
 

OpenAI has introduced new passwordless security settings for ChatGPT accounts, allowing users to opt for passkeys or physical security keys. At the same time, the generative AI firm has announced a partnership with hardware authentication device maker Yubico, offering a two-pack set of custom YubiKeys to users at a special price.

The new opt-in setting, named Advanced Account Security, removes password-based sign-in from ChatGPT and Codex accounts. Instead, users can opt for any FIDO-compliant security key or software-based passkeys.

The feature is built on FIDO2 and WebAuthn specifications, the same standards adopted by Google, Microsoft, GitHub, and other vendors for phishing-resistant authentication.

The partnership with Yubico comes after OpenAI deployed its products internally to protect their employees and infrastructure from sophisticated phishing. The U.S.-based firm has been dealing with threats such as cybercriminals sending malware to OpenAI employees and attackers exploiting OpenAI’s organization creation and team invitation features to send spam emails from legitimate OpenAI addresses.

“We’ve made YubiKeys a standard part of how we protect OpenAI employees, and with Advanced Account Security, we’re making it easier for ChatGPT users to choose that same kind of phishing-resistant protection when it’s right for them,” says Dane Stuckey, chief information security officer at OpenAI.

Yubico will offer users a bundle consisting of the YubiKey C Nano, designed to remain seated in a laptop port for daily authentication, and the YubiKey C NFC, intended for backup and cross-device use across laptops and mobile devices.

“Ultimately, our intent is to drastically reduce the threat of unauthorized access to sensitive data in OpenAI accounts worldwide,” says Yubico CEO Jerrod Chong.

Yubico is also looking towards securing AI workflows as more companies rush to adopt AI, leading to security gaps. The Sweden-based firm has partnered with Delinea to provide hardware-attested proof of human authorization for high-consequence agentic actions, including audit trails that bind every automated action to a verified human.

Related Posts

Article Topics

 |   |   |   |   |   |   | 

Latest Biometrics News

 

Face biometrics use cases outnumbered only by important considerations

With face biometrics now used regularly in many different sectors and areas of life, stakeholders are asking questions about a…

 

Biometric Update Podcast explores identification at scale using browser fingerprinting

“Browser fingerprinting is this idea that modern browsers are so complex.” So says Valentin Vasilyev, Chief Technology Officer of Fingerprint,…

 

Passkeys now pervasive but passwords persist in enterprise authentication

Passkeys are here; now about those passwords. Specifically, passkeys are now prevalent in the enterprise, the FIDO Alliance says, with…

 

Pornhub returns to UK, but only for iOS users who verify age with Apple

In the UK, “wanker” is not typically a term of endearment. However, the case may be different for Pornhub, which…

 

Europol operated ‘shadow’ IT systems without data safeguards: Report

Europol has operated secret data analysis platforms containing large amounts of personal information, such as identity documents, without the security…

 

EU pushes AI Act deadlines for high-risk systems, including biometrics

The EU has reached a provisional agreement on changes to the AI Act that postpone rules on high-risk AI systems,…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events