ChatGPTの高度なアカウントセキュリティ機能を発表

#Tech

ChatGPTの高度なアカウントセキュリティ機能を発表

OpenAIは、デジタル攻撃のリスクが高いユーザーや、より強固なアカウント保護を求めるユーザー向けの新しい設定「高度なアカウントセキュリティ」を導入しました。

この機能は、パスキーによるログインを必須とし、メールやSMSによる復旧を無効化するなど、複数のセキュリティ強化策をまとめて提供します。

セッションの短縮やアクティブセッションの管理機能も含まれ、機密情報を扱うユーザーはモデル学習からの除外も自動的に適用されます。

今後は、企業環境など、より幅広いユーザーへの展開も検討されています。

OpenAIは、ChatGPTアカウントのセキュリティを大幅に強化する新機能「Advanced Account Security」を導入しました。これは、デジタル攻撃のリスクが高いユーザーや、最高レベルの保護を求めるユーザー向けに提供されるオプション設定です。アカウント乗っ取りを防ぐための複数の高度なセキュリティ対策が一元化されています。

サインインとリカバリーの厳格化

この新機能では、サインイン方法が強化されます。パスワードベースのログインは無効化され、パスキーや物理的なセキュリティキーの使用が必須となります。これにより、フィッシング攻撃に対する耐性が高まります。また、アカウントリカバリーについても厳格化され、メールやSMSによるリカバリーは利用できなくなります。代わりに、バックアップパスキーやセキュリティキー、リカバリーキーといったより強固な方法が求められます。

セッション管理とデータ保護の強化

セキュリティ強化の一環として、サインインセッションの有効期間が短縮されます。これにより、デバイスやアクティブセッションが侵害された場合の露出期間を最小限に抑えます。さらに、ユーザーはログインの通知を受け取り、どのデバイスでアカウントが利用されているかを一元的に確認・管理できるようになります。また、特に機密性の高い情報を扱うユーザーは、会話データがモデルのトレーニングに使用されないよう、自動的に設定が適用されます。

セキュリティキー導入と利用義務化の動き

OpenAIは、ハードウェア認証のリーダーであるYubicoと提携し、物理セキュリティキーの利用を促進しています。YubiKey C NanoやYubiKey C NFCといった製品のカスタマイズされたバンドルを、Advanced Account Securityの導入と合わせて提供します。なお、この機能は任意で利用可能ですが、サイバー分野の検証済み防御者(Trusted Access for Cyber)は、2026年6月1日までにこのAdvanced Account Securityの有効化が義務付けられる予定です。

まとめ

AIが生活やビジネスの基盤となる中で、プライバシーとセキュリティの確保は極めて重要です。OpenAIは今後も、エンタープライズ環境を含むより幅広いユーザー層に対して、より強力なアカウント保護を提供していく方針です。

原文の冒頭を表示(英語・3段落のみ)

Today, we’re introducing Advanced Account Security, a new opt-in setting for ChatGPT accounts, designed for people at increased risk of digital attacks, as well as for those who want the strongest account protections available. It brings together a set of heightened security measures that help safeguard against account takeover while making those protections easier to activate in one place. Once enrolled, Advanced Account Security protects users in Codex as well.People are turning to AI for deeply personal questions and increasingly high-stakes work. Over time, a ChatGPT account can hold sensitive personal and professional context, and sit at the center of connected tools and workflows. For some people, like journalists, elected officials, political dissidents, researchers, and those who are especially security-conscious, the stakes are even higher.This effort is part of our broader cybersecurity action plan⁠(opens in a new window) to broaden access to the technologies that can help protect communities, critical systems, and our national security. We want users to have the controls to make the security and privacy choices that are right for them. At the same time, we want to ensure users understand that the increased protection of Advanced Account Security comes with an increased responsibility for account recovery.Advanced Account Security brings together a series of controls that strengthen sign-in protections, tighten account recovery, reduce exposure from compromised sessions, and give users more visibility into account activity. It’s available to opt into in the Security section of users’ ChatGPT accounts on web. Protection applies to both ChatGPT and Codex accounts that are accessed through that login.Stronger sign-in methods. Advanced Account Security requires passkeys or physical security keys while disabling password-based login, helping make phishing-resistant sign-in the default for people who need it most.More secure account recovery. If a user’s email account or phone number is compromised, an attacker may try to use one of them to gain access to their ChatGPT account via e-mail or SMS based recovery. To reduce this risk, Advanced Account Security disables email and SMS recovery and requires stronger recovery methods: backup passkeys, security keys, and recovery keys. Because account recovery is restricted to these more secure methods, OpenAI Support will not be able to assist with account recovery for users enrolled in Advanced Account Security.Shorter sessions and clearer session management. Sign-in sessions are shortened to reduce the window of exposure if a device or active session is compromised. Users also receive alerts when there is a login to their account, and they can review and manage the active sessions across the various devices they’re signed into.Automatic training exclusion. People working with especially sensitive information may opt not to have those conversations used for model training. With Advanced Account Security enabled, that preference is automatic: conversations from those accounts will not be used to  train our models.Using physical security keys, such as YubiKeys, is one of the strongest defenses against phishing. To make that level of protection easier to access, we have partnered with Yubico, a leader in hardware-based authentication and account protection, to offer our users preferred pricing on a customized bundle of best in class security keys. The YubiKey C Nano is designed to stay in your laptop for simple, low-friction daily authentication, and the YubiKey C NFC for backup, and use across laptops and mobile devices. We’re launching this partnership as part of Advanced Account Security, but the bundle will be available to all eligible users in their security settings on web so more people can adopt stronger, phishing-resistant account protection. Users will also be able to use any other FIDO-compliant security key, or use software-based passkeys.We continue to expand programs that give verified defenders access to more capable and permissive models, and we need to ensure that the accounts of those defenders are protected with our most advanced security protections. Individual members of Trusted Access for Cyber accessing our most cyber capable and permissive models will be required to enable Advanced Account Security beginning June 1, 2026. Organizations with trusted access can, as an alternative, attest that they have phishing resistant authentication as part of their single sign-on workflow.OpenAI is becoming the core infrastructure for AI, making it possible for people around the world and businesses, big and small, to just build things. The broad consumer reach of ChatGPT creates a powerful distribution channel into the workplace, where demand is rapidly shifting from basic model access to intelligent systems that reshape how businesses operate. Developers build on and expand the platform by leveraging our APIs, and Codex is transforming how developers turn ideas into working software. As AI becomes increasingly embedded in our lives, it is more important than ever to ensure that users have the controls they need to help protect their privacy and security.Privacy and security are foundational to how we build all of our products and we’ll continue investing in protections that give people more control and stronger safeguards over time. We expect to extend this work to additional audiences, including enterprise environments, where stronger account security can matter just as much.

※ 著作権に配慮し、引用は冒頭3段落までです。続きは元記事をご覧ください。

元記事を読む ↗