Does this apply to anyone who verified their ID to get access to the slightly less restricted Codex versions, or only to security professionals who have the almost-entirely unrestricted version?
Seriously though if you are letting agents do whatever they want without a PR process that requires hardware authentication or proof of presence, you are putting your code and your org at high risk.
Interestingly, I had to switch to my unpaid OpenAI account to access it. I suspect this is because my paid account is registered to a custom.com email address.
I was looking at something similar a couple of days ago.
I think a physical key like a yubi key is a great way to fight bot traffic.
And apparently cloudflare already ran project to test this out, and found some small drawbacks.
So they proposed CAP together with other orgs
https://developers.cloudflare.com/fundamentals/reference/cry...
This might be an extreme case of that, but I can see us going in that direction
11 comments
[ 11.1 ms ] story [ 103 ms ] threadSeriously though if you are letting agents do whatever they want without a PR process that requires hardware authentication or proof of presence, you are putting your code and your org at high risk.
https://www.yubico.com/store/partner/openai/
Interestingly, I had to switch to my unpaid OpenAI account to access it. I suspect this is because my paid account is registered to a custom.com email address.
This might be an extreme case of that, but I can see us going in that direction