Skip to content

OpenAI Introduces Hardware Passkeys for Cybersecurity Models

Bottom line: OpenAI requires users of advanced cybersecurity models to use hardware security keys instead of software-based authentication.

OpenAI is tying access to powerful security models in the “Trusted Access for Cyber” program to hardware-backed passkeys starting in September. Members who do not set up the new authentication method will only have access to standard models.

Effective September 1, 2024, members of OpenAI’s “Trusted Access for Cyber” (TAC) program must set up a hardware-backed passkey to access advanced security models such as GPT-5.6. These are USB devices that store authentication data locally. Those who do not enable “Advanced Account Security” will lose access to the more powerful cybersecurity models and will be downgraded to the standard version.

The TAC program is currently used by thousands of individuals and hundreds of teams responsible for protecting critical infrastructure. These models can be used to identify security vulnerabilities—a circumstance that creates a high incentive for attackers to gain unauthorized access. The strict access control addresses this risk directly: stolen or compromised login credentials lose their value without the physical key.

Hardware-backed passkeys—OpenAI is working here with Yubico, the manufacturer of the YubiKey series—are considered significantly more resistant to phishing attacks than traditional passwords or SMS-based two-factor methods. The cryptographic keys cannot be copied, cannot be remotely read, and cannot be synchronized between devices. According to Yubico CEO Jerrod Chong, this approach significantly complicates large-scale account abuse and increases costs for attackers who rely on trading compromised accounts.


Source: www.it-daily.net · Published July 14, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: