Live Stream Announcement
On July 28 at 22 o’clock, I will be doing a YouTube Live stream for the first time in a while.
The topics are the following public consultations issued by the Ministry of Internal Affairs and Communications and the Financial Services Agency, along with other general identity-related news.
References
- Request for Comments on the “Interim Organization of Issues (Draft) by the Study Group on Measures to Deter Access to Online Casinos”
- Draft Partial Amendments to the “Comprehensive Guidelines for Supervision of Financial Instruments Business Operators, etc.” (addressing so-called fraudulent securities transactions)
- Draft Report on Improving the User Environment in Response to Issues Surrounding the Use of ICT Services
Please join us.
Correction to a Statement Made During the Live Stream
At around 1:44:20, I said that Google’s ZKP implementation was apparently considerably faster than BBS, but I meant JWP+SNARK, not BBS. I sincerely apologize.
Added 2025-08-08
Below are a table of contents and an AI-extracted overview for reference.
00:00:00 Introduction
00:02:26 Study Group on Deterring Access to Online Casinos
00:12:11 History of the Blocking Issue and Current Debate
00:20:17 Details and Interesting Points in the Draft Interim Organization of Issues
00:40:23 FSA Draft Amendments to Supervisory Guidelines
00:57:44 Draft Report on Improving the Environment for Using ICT Services
01:07:30 Other Public Consultations and the Importance of Measures for Older People
01:19:20 Identity-Related News (January–March)
01:47:36 Identity-Related News (April–July)
Summary
In this video, Mr. Sakimura and Mr. Hayashi discuss several matters currently open for public comment, including ways to deter access to online casinos, amendments to the FSA’s supervisory guidelines, and a draft report on improving the environment for using ICT services. First, Mr. Hayashi explains in detail the study group’s draft interim organization of issues concerning deterrence of access to online casinos and describes the problems and technical challenges of blocking. Next, Mr. Sakimura explains the FSA’s draft amendments to its supervisory guidelines and emphasizes the importance of phishing-resistant authentication methods. They also discuss the draft report on improving the environment for using ICT services, including how communication logs should be retained. In the second half, Mr. Sakimura presents identity-related news from the past 7 months, covering a broad range of topics such as adding My Number cards to smartphones, digital-ID developments in various countries, and challenges with AI-based identity verification. Throughout, the discussion emphasizes balancing security and convenience in digital identity and the importance of privacy protection.
Chapters
Study Group on Deterring Access to Online Casinos
Mr. Hayashi explained the draft interim organization of issues produced by the Ministry of Internal Affairs and Communications’ study group on how to deter access to online casinos. Public comments on the matter are being accepted until August 15. Using materials from his presentation on the topic at a MyDataJAPAN2025 event, he emphasized that it raises important issues concerning Internet freedom. He noted that large volumes of formulaic public comments are ineffective and stressed the importance of submitting comments with appropriate substance. He also compared it with the blocking debate during the pirate-site Manga-Mura issue in 2018. Although the current discussion is being conducted properly, he was concerned that it has attracted little attention. Because this is an important matter involving Internet freedom and privacy, he emphasized the importance of submitting public comments.
History of the Blocking Issue and Current Debate
Mr. Hayashi explained the history of the blocking issue, organizing it into child-pornography blocking around 2005, the pirate-site issue around 2018, and the current discussion targeting online casinos—3 stages in all. He assessed the current interim organization of issues as very well compiled, neutral, and thorough in identifying the issues. He recommended materials by Mr. Ibanonoguchi and Mr. Tateishi of the Internet Content Safety Association and explained the technical and legal challenges of blocking. In particular, he pointed out that blocking to combat child pornography costs ¥30 million annually, that blocking itself may be illegal, and that network engineers face litigation risk. As his personal view, he said blocking is overkill for the online-casino problem and is not the optimal solution if it requires sacrificing freedom of communications.
Details and Interesting Points in the Draft Interim Organization of Issues
Mr. Hayashi explained the details of the draft interim organization of issues. The document is only 93 pages long, with a table of contents fitting into 7 pages. It organizes the background, current state of online casinos, need for a comprehensive response, and methods of deterring access. Particularly interesting points include the revision of the Basic Plan for Promoting Measures Against Gambling Addiction this fiscal year to include online-casino countermeasures for the first time, and passage in the current Diet session of a bill amending the Basic Act on Measures Against Gambling Addiction to prohibit operating online-casino sites and disseminating information that directs users to them. It also discusses restricting credit-card use to deter payments and the difficulty of technical access-deterrence methods. Regarding the examples from France and the United Kingdom, Mr. Hayashi asked, “Do we need to imitate countries that lag behind on the Internet?”
FSA Draft Amendments to Supervisory Guidelines
Mr. Sakimura explained the FSA’s draft partial amendments to its comprehensive supervisory guidelines for financial instruments business operators and others. The comment deadline is August 18, and the main requirement is to introduce phishing-resistant authentication. Referring to his blog, he explained why one-time passwords, including SMS authentication, cannot prevent phishing and why passkeys are phishing resistant. He also noted that securities companies without APIs may encounter problems integrating with portfolio-management software. As a short-term measure, he suggested allowing read-only access using OTPs while requiring phishing-resistant authentication for transactions. Mr. Hayashi said countermeasures must assume that humans are susceptible to deception and that mechanisms such as APIs are needed. While noting that passkeys are not a silver bullet, Mr. Sakimura emphasized their effectiveness against phishing.
Draft Report on Improving the Environment for Using ICT Services
Mr. Sakimura explained the draft report on improving the environment for using ICT services. The deadline is August 4. Professor Shishido chairs the group, whose members include Professor Mori, Professor Tatsuhiko Yamamoto, and Ms. Otani. At 93 pages, the report is lengthy, but it organizes issues including countermeasures against improper use, user information, and communication-log retention. From an identity perspective, Mr. Sakimura said he was interested in the second part’s rules on identity verification for mobile phones, corporate agents, and reliance on other companies’ identity-verification results. Mr. Hayashi observed that this report, too, focuses on measures by those being attacked, such as crime and fraud countermeasures. Mr. Sakimura introduced proposed guideline amendments in the working-group section on communication logs and emphasized the importance of commenting on them.
Other Public Consultations and the Importance of Measures for Older People
Mr. Sakimura also mentioned the “Draft Report of the Study Group on Realizing a Safe and Secure Metaverse” and identity verification in the metaverse. Mr. Hayashi noted that although there is much discussion of protecting children and minors, measures for older people may be a more urgent issue. Defining problems with older people’s cognitive ability is difficult and may risk discrimination, but he said the discussion must not be avoided. Mr. Sakimura introduced Professor Kato of Toyo University’s warning that “vulnerability filtering” and “vulnerability lists” could be abused, saying careful consideration is needed. He also addressed age-verification technology and explained that simple age verification could be combined with J-Station technology that estimates age from behavior and faces.
Identity-Related News (January–March)
Mr. Sakimura presented identity-related news from the past 7 months. News from January included the Digital Agency’s launch of a corporate-information database covering 5 million companies, Google’s announcement concerning fingerprinting as an alternative to third-party cookies, and problems with identity verification in Tokyo’s My Number card app. In February, topics included preventing ticket resale using My Number cards, an update to Google’s password manager, and digitizing registration procedures for national qualifications. In March, reports included Doshi Village in Yamanashi Prefecture and Osaka City launching “no-writing service counters,” a Philippine digital-verification-services bill passing a regulatory committee, and moves to consolidate services around the My Number card. He also introduced the problem of malicious extensions impersonating password managers to steal sensitive information.
Identity-Related News (April–July)
Mr. Sakimura continued with news from April through July. In April, a driver’s-license reading app was released and inheritance procedures using My Number were shortened. In May, NEC and Waseda University began joint research toward practical deployment of DIDs and VCs, and authorities considered requiring notification of addresses and other information to combat international-remittance fraud. In June, My Number cards became available on iPhones, and Rakuten launched an account-opening service using My Number cards. In July, reports described worsening fraud and impersonation using AI, particularly expanding voice-phishing damage and cases of bypassing identity verification with AI. Other topics included the start of emergency use of My Number health-insurance cards and stronger digital-ID authentication in Australia. Mr. Hayashi and Mr. Sakimura expressed concern that appropriate regulation and countermeasures have not kept pace with AI’s rapid development.
Related posts

FSA to Revise Supervisory Guidelines, Moving to Mandate Phishing-Resistant Authentication. Despite What Some Articles Say, This Does Not Mean Biometric Authentication! Public Comments Due by 8/18
On 15, the Financial Services Agency began accepting public comments under the title “Publication of Proposed Partial Amendments to the Comprehensive Guidelines for Supervision of Financial…
We Submitted Public Comments on the FSA’s Proposed Partial Amendments to the “Comprehensive Guidelines for Supervision of Financial Instruments Business Operators, etc.”
The U.S.-based OpenID Foundation submitted the following public comments on the Proposed Partial Amendments to the “Comprehensive Guidelines for Supervision of Financial Instruments Business Operators, etc.”…

FY 2024: Identity-Related Developments Are Moving Too Fast This Fiscal Year—A Linked List, Updated Regularly
On a whim today, I tried making a list of digital identity-related developments since the start of this fiscal year, but they have been coming one…
