The U.S.-based OpenID Foundation submitted the following public comments on the Proposed Partial Amendments to the “Comprehensive Guidelines for Supervision of Financial Instruments Business Operators, etc.” (← addressing so-called fraudulent securities transactions). Because the U.S.-based OpenID Foundation’s website is English-only and has no suitable place for the Japanese text, I am posting it here.

Public Comments on the Draft Comprehensive Guidelines for Supervision of Financial Instruments Business Operators, etc. (Comparison Table of Old and New Provisions)

1. Assessment of the FSA and Significance of the Proposed Amendments

First, we express our deep respect for the overall design of the proposed amendments. These revisions to the supervisory guidelines present specific and realistic guidance enabling the industry as a whole to respond effectively to increasingly sophisticated cyberthreats such as phishing and unauthorized access, and are extremely valuable. We particularly commend the inclusion of internationally advanced requirements such as mandatory phishing-resistant multi-factor authentication, stronger behavioral detection, and systematized measures to prevent fraudulent transactions. The structure encouraging use of industry guidelines and information-sharing organizations such as ISACs is not merely regulatory but constitutes a practical framework premised on continuous improvement, and can be regarded as a model for supervisory guidance.

2. Observations and Recommendations for Improvement

(1) p. 5: Positioning of the Prohibition on Links in Email and SMS

The proposed amendments state that “URLs for pages prompting password entry and login links should not be included in email or SMS.” While important for user protection, legitimate operational reasons for sending links also exist, including password-reset links, magic links, and WebOTP-compatible SMS. WebOTP in particular is highly phishing-resistant because browser integration automatically enters the code on the correct site without human intervention.
At the same time, attackers can be expected to continue sending convenient messages containing links.Rather than an absolute prohibition, the rule should be “prohibited in principle, permitted only when no appropriate alternative exists,” and should be moved later in the document as a “supplementary security measure.” This would better balance user convenience and security.

(2) p. 5: Positioning of Measures for Confirming Legitimate Sites

“Measures enabling users to confirm proof that the site they are accessing is authentic” are also important, but methods relying on human visual inspection have limited phishing resistance. These should likewise be listed later as supplementary measures, while the primary defenses should be automated, cryptography-based, phishing-resistant authentication technologies.

(3) p. 6: Implementation and Mandatory Use of Phishing-Resistant Multi-Factor Authentication

“Mandatory phishing-resistant multi-factor authentication for important operations such as login, withdrawal, and changing the destination bank account for withdrawals” is extremely important. In practice, however, cases are often seen in which customers revert to password authentication themselves after setup because advanced authentication is troublesome, or in which password authentication remains available only through a special transaction path. Needless to say, setting strong authentication for transactions is meaningless if a password-authentication path remains.
It is therefore desirable to specify a mechanism under which passwords are abolished once strong authentication is configured and users cannot revert. Building on the current concept of risk-based authentication, phased application such as passwords for login and passkeys for transactions should also be presented as an option. This would allow Personal Finance Managers (PFMs) to remain usable even with securities companies that do not provide APIs, while reducing risk. In the medium term, simultaneous cutover to API provision and strong authentication would help prevent fraud while minimizing impact on consumers.

(4) Ensuring Security When Registering Authentication Methods

There is a risk that an attacker could use a password login as a foothold to register the attacker’s own passkey. It should therefore be specified that initial registration of strong authentication such as a passkey is permitted only within a session following strong identity verification, such as public personal authentication.

(5) p. 6: Continuous Application of Behavioral Detection

The current proposal recommends behavioral detection as an interim measure until passkeys become mandatory. However, because session hijacking and unauthorized operations can still occur after passkeys are introduced, behavioral detection and behavioral analysis should remain permanently mandatory.

(6) p. 6: Risks of Account Lockout and Alternatives

“Automatic account lockout after consecutive authentication failures” can be exploited for large-scale account-lockout and call-center-saturation attacks through DoS, particularly when sequential customer numbers are used as login identifiers. An attacker could then exploit the resulting confusion to take over accounts. Against automated brute force, delayed responses (for example, waiting 1 minutes) or additional authentication requirements are effective; account lockout should be positioned as a last resort.

(7) Strengthening Session Security and Inter-Provider Coordination

The proposal appears somewhat thin from the perspective of session security. Including privilege restrictions based on detecting changes in the browser or IP address sending a cookie and inter-provider sharing of anomalous-transaction detection information (for example, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and National Security Agency (NSA) recommend using the OpenID Shared Signals Framework) would enable broad fraud prevention.

(8) Revising Terminology: From “Multi-Factor Authentication” to “Strong Authentication” or “Secure Customer Authentication”

The repeated qualification “phishing-resistant” probably makes the intent sufficiently clear, but the term “multi-factor authentication” is generally too broad and risks encouraging mechanical adoption of low-quality multi-factor authentication. What this proposal truly needs to emphasize is resistance to various threats, including phishing resistance. Replacing or supplementing the terminology would clarify the intent and should produce qualitative improvements in practice.

3. Conclusion

The proposed amendments are not merely formal regulation, but emphasize effectiveness in light of the latest attack methods and technological developments. We regard them as an advanced effort to achieve both user protection and convenience. The recommendations above are intended to achieve both stronger defenses and operational feasibility in light of current operational practice and the latest international developments. We express our strong expectations and respect for the FSA’s continued leadership in developing guidance of this high standard.

Related posts