2fa security for accounts

OpenAI has an option to create an account with only an email address without tying it to Google or another service, but it doesn’t offer a 2fa option for this type of account. This type of account can also store a credit card, set usage limits and create/invite users. This is highly irresponsible from a security perspective. You should offer a 2fa option for accounts that sign up through an email address.

5 Likes

I second this!

Preferably via security keys.

I second your seconding of this!

Why no DUO mobile support?

From a security point of view, this feature is highly needed.

While Google and Microsoft could take care of that, not all organization use those providers. Enabling Two-Factor Authentication could potentially help serious security incidents.

If enabling 2FA, please allow for more than just one option (or at least allow for a standard option like TOTP).

2 Likes