메뉴
BL
TechCrunch AI • 37일 전

보안 연구자들, OpenAI 사이버 프로그램 접근 권한 갑작스럽게 취소당해

IMP
5/10
핵심 요약

여러 보안 연구자들이 OpenAI의 제한 접근 사이버보안 프로그램 TAC(Trusted Access for Cyber)의 최신 등급인 'Daybreak Blue' 접근 권한이 갑자기 취소되었다고 보고했습니다. OpenAI는 기술적 오류 때문이라고 해명하며 재인증을 요청했는데, 피해자들이 모두 미국과 유럽 외 지역 거주자여서 지역 제한 가능성이 제기되고 있습니다.

번역된 본문

여러 보안 연구자들이 OpenAI가 자사 AI 도구를 사이버보안 연구에 사용할 때 일부 제한을 해제해주는 제한 접근 프로그램에 대한 접근 권한을 갑자기 취소했다고 밝혔습니다. OpenAI는 이 문제가 오류로 인해 발생한 것이라고 확인했습니다.

수요일, OpenAI 공식 지원 포럼과 X(구 트위터)에서 여러 연구자들이 '사이버 신뢰 접근(Trusted Access for Cyber, TAC)' 프로그램에 대한 접근 권한이 취소되었다고 보고했습니다. 이들은 ChatGPT의 사이버(Cyber) 페이지를 열었을 때 본인 신원을 확인할 수 없거나 계정이 "현재 자격이 없다"는 메시지가 나타났다고 말했습니다.

TAC는 OpenAI가 검증된 연구자들에게 일반 사용자용 모델보다 사이버보안 안전장치를 덜 적용한 최신 AI 모델에 접근할 수 있도록 하는 특별 프로그램입니다. Anthropic도 '사이버 검증 프로그램(Cyber Verification Program, CVP)'이라는 유사한 프로그램을 운영하고 있습니다.

TAC와 CVP의 취지는 신뢰할 수 있는 방어 연구자들에게 더 강력한 모델을 제공해 기업에 버그와 취약점을 신고하게 하고, 결함이 더 빨리 패치되도록 하는 것입니다. 또한 사이버 범죄자와 악의적인 해커가 이런 모델에 접근해 버그를 찾고 해킹용 익스플로잇을 개발하는 것을 막는 것도 목적입니다. TAC 접근 권한을 얻으려면 사이버보안 연구자는 신분증을 제출하고 OpenAI의 검증을 받아야 합니다.

현재로서는 이 연구자들의 TAC 접근 권한이 취소된 이유와 몇 명이나 이 문제를 겪었는지 완전히 명확하지 않습니다. TechCrunch는 이 문제를 겪었다고 말한 5명의 연구자와 인터뷰했습니다.

한 연구자는 OpenAI가 보낸 이메일에서 TAC의 최신 검증 등급인 'Daybreak Blue'에 대한 접근 권한이 "일부 사용자에게 영향을 미치는 기술적 문제로 인해" 취소되었다고 안내했다고 말했습니다. 이 연구자가 TechCrunch와 공유한 메시지에는 "이것은 저희 측의 문제였으며, 저희가 제공하고자 하는 사용자 경험이 아닙니다"라고 적혀 있었습니다.

OpenAI 포럼의 한 스레드에서 한 연 researcher는 공식 지원팀에 문의한 후 회사가 일부 사용자가 Daybreak Blue 접근 권한을 잃게 만든 "최근 기술적 문제"를 언급했다고 밝혔습니다. 두 안내 모두에서 OpenAI는 연구자들에게 재신청하고 검증 절차를 완료하라고 요청했습니다.

TechCrunch와 인터뷰한 모든 연구자는 미국과 유럽 외 지역에 거주하고 있다고 밝혀, 권한 취소가 특정 지역으로 제한되었을 가능성을 시사합니다. OpenAI는 TechCrunch에 "한정된 사용자의 Daybreak Blue 접근 권한이 더 이상 활성 상태가 아니며 접근을 유지하려면 재검증이 필요하다"고 밝힌 자사 트윗을 안내했습니다.

8월 10일 출시된 Daybreak Blue는 개인 연구자를 위한 최신 등급으로, OpenAI에 따르면 "공인된 방어 보안 작업에 맞춰 안전장치를 조정한 GPT-5.6 Sol을 포함한 프론티어 범용 모델"에 대한 접근을 제공합니다. OpenAI는 "대부분의 방어자에게 권장되는 시작점으로, 취약점 발견, 보안 코드 리뷰, 악성코드 분석, 사고 대응, 패치 검증을 지원합니다"라고 설명했습니다. 같은 날 회사는 사이버보안 연구 전용으로 제작된 모델에 접근할 수 있는 더 높은 등급인 'Daybreak Red'도 도입했으며, 이 등급은 검증된 사용자가 "공인된 취약점 연구, 익스플로잇 검증, 보안 테스트"를 수행할 수 있게 합니다.

최근 몇 달간 방어적·공격적 보안 연구자 모두 Anthropic과 OpenAI가 부과한 안전장치에 대해 불만을 토로하며, 이러한 안전장치가 정당한 연구 활동을 방해한다고 주장해 왔습니다.

OpenAI의 코멘트를 반영해 업데이트됨.

원문 보기
원문 보기 (영어)
Several security researchers say OpenAI suddenly revoked their access to a limited-access program that removes some restrictions on using its AI tools for cybersecurity research. OpenAI confirmed that the issue was caused by an error. On Wednesday, multiple researchers on OpenAI’s official support forums and on X reported having their access to the Trusted Access for Cyber (TAC) program revoked. The people said that when they opened ChatGPT’s Cyber page , a message appeared saying their identity could not be verified or that their account "is ineligible at this time.” TAC is a special program through which OpenAI offers vetted researchers access to the company’s most advanced AI models with fewer cybersecurity guardrails than the models that regular users can access. Anthropic offers a similar program called the Cyber Verification Program , or CVP. The idea behind TAC and CVP is to give trusted defenders better models so they can report bugs and vulnerabilities to companies, with the aim of getting flaws patched faster. The goal is also to prevent cybercriminals and malicious hackers from accessing those models and use them to find bugs and develop exploits to hack companies. To get access to TAC, cybersecurity researchers have to submit an ID and be vetted by OpenAI. At this point, it’s not entirely clear why these researchers are getting their access to TAC revoked, nor how many people have had this issue. TechCrunch spoke to five researchers who said they have had this problem. One researcher said OpenAI sent an email saying that their access to Daybreak Blue, the latest vetted tier of TAC, was revoked “due to a technical issue affecting a limited number of users.” “This was an issue on our end, and not the user experience we want to deliver,” read the message, which the researcher shared with TechCrunch. In a thread on OpenAI’s forums, a researcher wrote that after they reached out to the official support, the company also cited a "recent technical issue" that caused some users to lose access to Daybreak Blue. In both messages, OpenAI asked the researchers to reapply and complete the verification process. All the researchers TechCrunch spoke to said they live outside of the U.S. and Europe, suggesting the revocations may be limited to certain regions. OpenAI referred TechCrunch to a tweet , in which the company said a "limited set of users’ access to Daybreak Blue is no longer active and they will need to re-verify to maintain their access." Daybreak Blue is the latest tier for individual researchers that grants access to “frontier general-purpose models, including GPT‑5.6 Sol, with safeguards tailored to authorized defensive security work,” according to OpenAI , which launched it on August 10. “It is the recommended starting point for most defenders, supporting vulnerability discovery, secure code review, malware analysis, incident response, and patch validation.” At the same time, the company also introduced a higher tier called Daybreak Red that gives access to models made specifically for cybersecurity research, which allow vetted users to do “authorized vulnerability research, exploit validation, and security testing.” In recent months, both defensive and offensive security researchers have complained about the guardrails imposed by Anthropic and OpenAI, arguing that the guardrails prevent them from doing legitimate work. Updated with comment from OpenAI. Topics AI , cybersecurity , opeanai , Security When you purchase through links in our articles, we may earn a small commission . This doesn’t affect our editorial independence. Lorenzo Franceschi-Bicchierai Senior Reporter, Cybersecurity Lorenzo Franceschi-Bicchierai is a Senior Writer at TechCrunch, where he covers hacking, cybersecurity, surveillance, and privacy. You can contact or verify outreach from Lorenzo by emailing lorenzo@techcrunch.com , via encrypted message at +1 917 257 1382 on Signal, and @lorenzofb on Keybase/Telegram. View Bio October 13 - 15 San Francisco Scale faster. Grow your portfolio. Gain practical expertise. No matter your goal, Disrupt can empower you. Save up to $300 toda y! REGISTER NOW Most Popular Stripe will reportedly acquire AI gateway startup OpenRouter for $7B+ Anthony Ha Anthropic shares more details about how Claude’s new watermarks will work Anthony Ha 7 desk gadgets that can make your workday better Aisha Malik Apple proposes to take a 15% cut of purchases made outside the App Store Sarah Perez If Apple sends you a push notification alerting you to a spyware attack, take it seriously Zack Whittaker Anthropic set AI agents loose on the same task. They started a turf war. Rebecca Bellan Instagram introduces a redesigned wordmark Sarah Perez
관련 소식