ChatGPT advanced account security adds passkeys and hardware keys
Vulnerability: OpenAI enhances ChatGPT security with passkeys and hardware keys, disabling password login and email/SMS recovery.
Deep Analysis and Expert Commentary
OpenAI’s Advanced Account Security addresses phishing risks by eliminating password-based authentication and insecure recovery methods like email and SMS. Attackers often exploit these vectors through SIM swapping or credential stuffing. By enforcing passkeys or hardware keys, OpenAI reduces exposure to such attacks. The shortened session duration minimizes risks from compromised devices. The exclusion of conversations from model training caters to users handling sensitive data. The Yubico partnership and FIDO2 compliance ensure seamless integration with existing standards. Mandatory enrollment for Trusted Access for Cyber underscores the growing emphasis on phishing-resistant authentication in high-stakes environments.
Action Items
- Enable Advanced Account Security for ChatGPT and Codex accounts.
- Acquire and configure FIDO2-compliant hardware keys like YubiKeys.
- Ensure backup passkeys or recovery keys are securely stored.
- Review and update organizational SSO workflows to include phishing-resistant authentication.
Original Article Brief Intro
Help Net Security · 2026-05-03 · Vulnerability: OpenAI enhances ChatGPT security with passkeys and hardware keys, disabling password login and email/SMS recovery.
Related Terms and Notes
Techniques / TTPs
- FIDO2 — A standard for secure authentication, combining WebAuthn and CTAP protocols for phishing-resistant logins.
- passkeys — Cryptographic credentials stored on devices, replacing passwords with phishing-resistant authentication.
- phishing
- phishing-resistant authentication
Context Notes
- authentication
- FIDO2
- hardware security keys
- OpenAI
- passkeys
- YubiKey