Archive

tag: Authentication

Events

12th FIDO Tokyo Seminar - Towards a Password-Free World -

As I announced on X (I often don't have time to write blog posts, so I'd appreciate it if you could follow me on X as well), today is the 12th FIDO Tokyo Seminar ~Toward a Password-Free World~. The conference program (see below) will focus on ~Phishing Countermeasures and the Latest Trends Using "Passkeys"~. I will be appearing on the closing panel…

identity

[Breaking News] The future of digital IDs is changing! OpenID Foundation responds to regulations and market competition with third-party authentication services!

The OpenID Foundation, which sets international standards for digital identity, has announced the launch of a new authentication service in the second quarter of 2026! This groundbreaking service will strengthen collaboration with regulatory bodies and accreditation testing organizations, building upon the existing self-authentication service (which already boasts over 4,000 successful cases). Key features of the service include: Global regulatory compliance and enhanced market competition: compliance with national and regional regulations…

identity

Public comments have been submitted to the Financial Services Agency regarding the partial revision (draft) of the "Comprehensive Supervision Guidelines for Financial Instruments Business Operators, etc."

The following public comments have been submitted by the U.S. OpenID Foundation to the proposed amendments to the "Comprehensive Supervisory Guidelines for Financial Instruments Business Operators, etc." (← so-called measures against securities fraud). Since the U.S. OpenID Foundation's website is in English only, there is no appropriate place to post the Japanese version, so we are posting it here. Comprehensive Supervisory Guidelines for Financial Instruments Business Operators, etc. (Comparison Table of Old and New Versions)…

identity

Ministry of Internal Affairs and Communications Study Group on the Realization of a Safe and Secure Metaverse Announces 2025 Draft Report - Identity Verification, Privacy, and Accountability in the Metaverse (Public comments accepted until August 8th)

Update: Public comments are being accepted from August 4th to 27th. If you have any opinions, please submit them at https://www.soumu.go.jp/menu_news/s-news/01iicp01_02000126.html. Submission forms and other information can be found on this e-gov page. Today, July 23rd, 2025 (Wednesday), from 15:00 to 17:00, the Ministry of Internal Affairs and Communications held a meeting on "Realizing a Safe and Secure Metaverse…"

identity

The Japanese Financial Services Agency amends supervisory guidelines. Phishing-resistant authentication methods will become mandatory. It is not biometric authentication as some media say, however! Public comments are open until August 8th.

On the 15th, the Financial Services Agency (FSA) began soliciting public comments on a proposed amendment to the "Comprehensive Supervisory Guidelines for Financial Instruments Business Operators, etc." The deadline for submissions is August 18th (Monday) at 17:00 PM (must be received by this time). This matter concerns unauthorized access and fraudulent transactions (third-party) in internet trading services using customer information (login IDs, passwords, etc.) stolen through phishing sites impersonating securities company websites.

identity

The threat of real-time phishing that cannot be prevented by one-time passwords - The true nature of phishing resistance using passkeys

In recent years, phishing attacks targeting financial institutions and other organizations have become increasingly sophisticated, with a technique known as "real-time phishing" posing a particularly serious threat. This type of attack is known to even disable one-time passwords (OTPs), which were previously considered effective countermeasures against phishing attacks, forcing financial institutions to fundamentally redesign their identity verification systems.

OAuth

[Announcement] Is that QR code safe? ~ Threats and countermeasures lurking in cross-device authentication and authorization flows [YouTube Live]

On August 22nd (Thursday) at 8 PM, we will be hosting a YouTube Live broadcast titled "Is That QR Code Secure? ~ Threats and Countermeasures Lurking in Cross-Device Authentication and Authorization Flows," featuring @ritou, also known as Akita no Neko (Akita Cat). We're increasingly using QR codes to log in, but are they truly secure? There are many pitfalls in authentication and authorization across multiple devices…

Events

9/15 (Thu) 14:6 ~ "ISO Panel (5158th): Online identity verification (eKYC) - Overview of the new international standard ISO XNUMX and its potential uses" hosted by the Bank of Japan

On Thursday, September 15, 2022, from 2:00 PM to 3:30 PM, the Bank of Japan's Payment and Settlement Systems Department will host the "ISO Panel (6th): Online Identity Verification (eKYC) – Overview and Potential Applications of the New International Standard ISO 5158 –". The main theme will be the new international standard, guidelines for customer identification in mobile financial services…