메뉴
HN
Hacker News 14일 전

오픈AI, 사이버 보안 멤버 대상 하드웨어 패스키 도입 의무화

IMP
8/10
핵심 요약

오픈AI는 최첨단 AI 모델에 대한 접근 권한을 가진 '사이버 신뢰 액세스(TAC)' 멤버들에게 피싱에 강력한 하드웨어 기반 패스키(보안 키) 로그인을 의무화했습니다. 이는 기존의 소프트웨어 기반 통제나 구형 다중 인증(MFA)의 취약점을 극복하고, 해킹 계정을 악용하는 범죄 생태계를 원천 차단하기 위한 조치입니다. 유비코(Yubico)와의 협력을 통해 오픈AI는 내부 인프라를 보호하는 수준의 최고 등급 보안 환경을 제공합니다.

번역된 본문

오픈AI, 사이버 신뢰 액세스(Trusted Access for Cyber) 멤버의 ChatGPT 계정 로그인에 하드웨어 기반 패스키 의무화 저자: Jerrod Chong / 2026년 7월 9일

AI의 급격한 발전은 글로벌 사이버 보안 환경을 변화시키고 있습니다. 이러한 기술이 더욱 강력해짐에 따라 기술에 대한 접근을 보호하는 것이 점점 더 중요해지고 있습니다. 특히 취약점을 식별하고, 소프트웨어를 강화하며, 사이버 복원력을 개선하기 위해 노력하는 보안 연구원과 방어자들에게 있어서는 더욱 그렇습니다. 최첨단 AI 역량이 신뢰할 수 있는 사용자의 통제 아래 유지되도록 보장하기 위해, 현대적인 피싱 및 소셜 엔지니어링 공격을 견딜 수 있는 고급 계정 보호가 필요합니다.

오늘 오픈AI의 발표는 업계의 새로운 표준을 제시합니다. 9월 1일부터 사이버 신뢰 액세스(TAC)의 모든 개별 멤버는 최첨단 사이버 보안 모델에 대한 접근 권한을 유지하기 위해 하드웨어 기반 패스키(passkey)를 사용한 '고급 계정 보안(Advanced Account Security)'을 반드시 활성화해야 합니다. 또한, 오픈AI는 고위험 대상 및 관할 지역에 대한 접근 제한을 한층 더 강화하고 있습니다.

유비코(Yubico)는 AI 보안의 미래가 단순히 모델의 안전성에만 국한되지 않고, ID 및 인증 기반의 보증에 크게 좌우될 것이라고 확신합니다. 이해관계가 이토록 중요한 상황에서, 조직은 더 이상 쉽게 우회되거나 가로채일 수 있는 소프트웨어 기반 통제나 기존의 다중 인증(MFA)에 의존할 수 없습니다. 진정한 보안은 복사하거나 동기화할 수 없는 자격 증명을 기반으로 구축된, 피싱 방지가 가능한 하드웨어 기반의 신뢰 루트(root of trust)를 필요로 합니다. 하드웨어 기반 패스키로 TAC를 보호하면 위협 행위자가 대규모로 계정을 악용하기가 훨씬 더 어려워지고 비용이 많이 들게 됩니다. 진입 장벽을 획기적으로 높임으로써, 이러한 접근 방식은 침해된 계정을 생성, 검증 및 재판매하여 2차적으로 악용하는 데 의존하는 범죄 생태계를 파괴합니다.

유비키(YubiKey)로 ChatGPT 계정 보호하기 새로운 의무 규정에 부합하여 TAC 멤버들이 하드웨어 기반 보호로 전환하는 과정은 매우 매끄럽습니다. 오픈AI의 고급 계정 보안 프로그램을 통해 보안 키는 더 약한 폴백(fallback) 인증 방식을 의도적으로 비활성화함으로써 더 높은 수준의 신뢰 환경을 제공합니다. 이 파트너십을 통해 사용자는 오픈AI가 자체 인프라와 직원을 보호하기 위해 내부적으로 사용하는 것과 동일한 보안 체제를 구현할 수 있습니다. 이러한 전환을 지원하기 위해 기존 계정 보유자는 우대 가격으로 2개입 유비키 세트를 구매할 수 있습니다.

YubiKey C NFC - OpenAI: 현대의 모바일 인력에게 완벽합니다. 휴대폰이나 태블릿에 가볍게 템플릿하여 즉시 인증할 수 있습니다. YubiKey C Nano - OpenAI: 최고의 편의성을 위해 설계되었습니다. 노트북의 USB-C 포트에 꽂아두고 계속해서 편리하고 지속적인 보호를 누리세요.

일단 등록되고 나면, 사용자는 빠르고 완전히 비밀번호가 없는 경험을 통해 피싱을 방지할 수 있는 보안의 최고 표준을 경험하게 됩니다. 오늘 바로 유비키로 ChatGPT 계정을 보호하려면 chatgpt.com/advanced-account-security을 방문하거나 여기서 파트너십에 대한 전체 세부 정보를 읽어보세요.

태그: 에이전트 AI(Agentic AI), AI, 오픈AI

추천 게시물: 유비코(Yubico)란? 유비코는 현대 사이버 보안의 선구자로, 보안 인증 및 디지털 ID 솔루션을 전문으로 합니다. 또한 FIDO2/WebAuthn/패스키(passkey) 및 이전 버전인 FIDO 범용 2단계 인증(U2F) 프로토콜을 포함한 개방형 인증 표준 개발의 공동 창작자이자 기여자이기도 합니다. 유비코의 솔루션은 ID 보안을 강화하여 기업과 소비자가 안전하게 머물 수 있도록 지원합니다. 더 읽기

유비키 스포트라이트와 함께 작동: EgoMind의 Apoterix를 통한 기업 사이버 복원력을 위한 유비키 물류 전환 직원들에게 피싱을 방지하는 하드웨어 기반 유비키를 배포하는 것은 현대 보안 프로그램의 초석입니다. 조직이 이 방어의 황금 표준을 확장함에 따라 IT 팀은 종종 수천 명의 직원에 걸친 대규모 하드웨어 배포와 관련된 운영상의 문제(예: 장치 매핑, 재고 추적 및 자격 증명 수명 주기 관리)에 직면하게 됩니다. 이를 보장하기 위해... 더 읽기

구글 플레이 서비스

원문 보기
원문 보기 (영어)
OpenAI mandates hardware-backed passkeys for Trusted Access Cyber members to log into ChatGPT accounts Jerrod Chong Jerrod Chong July 9, 2026 The rapid advancement of AI is changing the global cybersecurity landscape. As these technologies become more powerful, safeguarding access to them is increasingly critical — particularly for the security researchers and defenders working to identify vulnerabilities, strengthen software and improve cyber resilience. People need advanced account protection that can withstand modern phishing and social engineering attacks, helping ensure state-of-the-art AI capabilities remain in the hands of trusted users. Today's announcement from OpenAI sets a new industry standard: starting September 1, all individual members of Trusted Access for Cyber (TAC) must enable Advanced Account Security using a hardware-backed passkey to retain access to frontier cyber models. Additionally, OpenAI is tightening access restrictions for high-risk entities and jurisdictions. At Yubico, we believe the future of AI security depends heavily on identity and authenticator assurance, not just model safety. When the stakes are this high, organizations can no longer rely on software-based controls or legacy multi-factor authentication (MFA), both of which are easily bypassed or intercepted. True security requires a phishing-resistant, hardware-backed root of trust built on credentials that cannot be copied or synced. Protecting TAC with hardware-backed passkeys makes accounts significantly more difficult and costly for threat actors to exploit at scale. By dramatically raising the barrier to entry, this approach disrupts the criminal ecosystem that relies on creating, validating, and reselling compromised accounts for downstream abuse. Securing your ChatGPT account with YubiKeys Moving to hardware-backed protection is a seamless process for TAC members aligning with the new mandate. Through OpenAI’s Advanced Account Security program, security keys provide a higher-assurance environment by deliberately disabling weaker fallback methods. This partnership allows you to replicate the identical security posture that OpenAI uses internally to safeguard its own infrastructure and employees. To facilitate this transition, a custom 2-pack of YubiKeys is available to existing account holders at preferred pricing. YubiKey C NFC - OpenAI: Perfect for the modern mobile workforce. Authenticate instantly with a simple tap against your phone or tablet. YubiKey C Nano - OpenAI: Designed for maximum convenience. Plug it into your laptop's USB-C port and leave it there for effortless, continuous protection. Once enrolled, users experience the gold standard of phishing-resistant security through a fast, entirely passwordless experience. To secure your ChatGPT accounts with YubiKeys today, visit chatgpt.com/advanced-account-security or read the full partnership details here . agentic AI , AI , OpenAI Talk to our team Share this article: Recommended Posts What is Yubico? What is Yubico? Yubico is a pioneer in modern cybersecurity, specializing in secure authentication and digital identity solutions. It is also a co-creator and contributor to the development of the open authentication standards, including FIDO2/WebAuthn/passkeys, and the earlier FIDO Universal 2nd Factor (U2F) protocol. Yubico’s solutions help to secure identities, enabling businesses and consumers to stay […] Read more Works with YubiKey Spotlight: Translating YubiKey logistics into enterprise cyber resilience with EgoMind’s Appterix Deploying hardware-backed, phishing-resistant YubiKeys to employees is a cornerstone of a modern security program. As organizations scale this gold standard of defense, IT teams often encounter the operational challenges inherent in managing large-scale hardware deployments across hundreds and thousands of employees – such as device mapping, inventory tracking and credential lifecycle management. To ensure the […] Read more Google Play Services adds support for NFC-enabled FIDO2 security keys: How Yubico makes Android passkey authentication seamless The continued global efforts behind passkey adoption represents one of the most exciting shifts in digital identity. Google recently took a big step forward by introducing an update to Google Play Services that allows account authentication through NFC security keys that support CTAP2 – including all Android versions starting with Android 9 and later. Google’s […] Read more