Researchers say OpenAI revoked their access to limited cyber program

Researchers say OpenAI revoked their access to limited cyber program

研究人员称 OpenAI 撤销了他们对网络安全有限访问计划的权限

Several security researchers say OpenAI suddenly revoked their access to a limited-access program that removes some restrictions on using its AI tools for cybersecurity research. OpenAI confirmed that the issue was caused by an error. 多位安全研究人员表示,OpenAI 突然撤销了他们对一个有限访问计划的权限,该计划旨在解除部分限制,以便他们能利用 OpenAI 的 AI 工具进行网络安全研究。OpenAI 已证实该问题是由系统错误导致的。

On Wednesday, multiple researchers on OpenAI’s official support forums and on X reported having their access to the Trusted Access for Cyber (TAC) program revoked. The people said that when they opened ChatGPT’s Cyber page, a message appeared saying their identity could not be verified or that their account “is ineligible at this time.” 周三,多名研究人员在 OpenAI 官方支持论坛和 X(原推特)上报告称,他们对“网络安全可信访问”(Trusted Access for Cyber, TAC)计划的访问权限被撤销。这些研究人员表示,当他们打开 ChatGPT 的网络安全页面时,系统弹出提示,称无法验证其身份,或者其账户“目前不符合资格”。

TAC is a special program through which OpenAI offers vetted researchers access to the company’s most advanced AI models with fewer cybersecurity guardrails than the models that regular users can access. Anthropic offers a similar program called the Cyber Verification Program, or CVP. TAC 是 OpenAI 的一项特殊计划,通过该计划,经过审核的研究人员可以访问该公司最先进的 AI 模型,且这些模型所受的网络安全防护限制比普通用户使用的模型更少。Anthropic 也提供类似的计划,称为“网络验证计划”(Cyber Verification Program, CVP)。

The idea behind TAC and CVP is to give trusted defenders better models so they can report bugs and vulnerabilities to companies, with the aim of getting flaws patched faster. The goal is also to prevent cybercriminals and malicious hackers from accessing those models and use them to find bugs and develop exploits to hack companies. TAC 和 CVP 的初衷是为可信的安全防御者提供更强大的模型,以便他们能向企业报告漏洞,从而加快漏洞修复速度。其目标还在于防止网络罪犯和恶意黑客利用这些模型寻找漏洞并开发攻击手段来入侵企业。

To get access to TAC, cybersecurity researchers have to submit an ID and be vetted by OpenAI. At this point, it’s not entirely clear why these researchers are getting their access to TAC revoked, nor how many people have had this issue. TechCrunch spoke to five researchers who said they have had this problem. 要获得 TAC 的访问权限,网络安全研究人员必须提交身份证明并经过 OpenAI 的审核。目前尚不完全清楚这些研究人员为何被撤销权限,也不清楚有多少人受到了影响。TechCrunch 采访了五位遇到此问题的研究人员。

One researcher said OpenAI sent an email saying that their access to Daybreak Blue, the latest vetted tier of TAC, was revoked “due to a technical issue affecting a limited number of users.” “This was an issue on our end, and not the user experience we want to deliver,” read the message, which the researcher shared with TechCrunch. 其中一位研究人员表示,OpenAI 发送了一封电子邮件,称他们对 Daybreak Blue(TAC 最新的审核层级)的访问权限被撤销,原因是“一个影响了少数用户的技术问题”。该研究人员向 TechCrunch 分享了这封邮件,其中写道:“这是我们方面的问题,并非我们希望提供的用户体验。”

In a thread on OpenAI’s forums, a researcher wrote that after they reached out to the official support, the company also cited a “recent technical issue” that caused some users to lose access to Daybreak Blue. In both messages, OpenAI asked the researchers to reapply and complete the verification process. 在 OpenAI 论坛的一个讨论帖中,一位研究人员写道,在联系官方支持后,公司同样提到了一个“近期技术问题”,导致部分用户失去了对 Daybreak Blue 的访问权限。在两份回复中,OpenAI 都要求研究人员重新申请并完成验证流程。

All the researchers TechCrunch spoke to said they live outside of the U.S. and Europe, suggesting the revocations may be limited to certain regions. OpenAI referred TechCrunch to a tweet in which the company said a “limited set of users’ access to Daybreak Blue is no longer active and they will need to re-verify to maintain their access.” 所有接受 TechCrunch 采访的研究人员都表示他们居住在美国和欧洲以外,这表明权限撤销可能仅限于特定地区。OpenAI 向 TechCrunch 指向了一条推文,公司在推文中表示:“一小部分用户的 Daybreak Blue 访问权限已失效,他们需要重新验证以维持访问权限。”

Daybreak Blue is the latest tier for individual researchers that grants access to “frontier general-purpose models, including GPT‑5.6 Sol, with safeguards tailored to authorized defensive security work,” according to OpenAI, which launched it on August 10. “It is the recommended starting point for most defenders, supporting vulnerability discovery, secure code review, malware analysis, incident response, and patch validation.” Daybreak Blue 是针对个人研究人员的最新层级,据 OpenAI 于 8 月 10 日发布的信息,该层级允许访问“前沿通用模型(包括 GPT-5.6 Sol),并配备了针对授权防御性安全工作量身定制的防护措施”。“这是大多数防御者的推荐起点,支持漏洞发现、安全代码审查、恶意软件分析、事件响应和补丁验证。”

At the same time, the company also introduced a higher tier called Daybreak Red that gives access to models made specifically for cybersecurity research, which allow vetted users to do “authorized vulnerability research, exploit validation, and security testing.” 与此同时,该公司还推出了一个更高级别层级,称为 Daybreak Red,提供专门用于网络安全研究的模型访问权限,允许经过审核的用户进行“授权漏洞研究、漏洞利用验证和安全测试”。

In recent months, both defensive and offensive security researchers have complained about the guardrails imposed by Anthropic and OpenAI, arguing that the guardrails prevent them from doing legitimate work. 近几个月来,防御性和攻击性安全研究人员都对 Anthropic 和 OpenAI 施加的防护限制表示不满,认为这些限制阻碍了他们进行合法的研究工作。