SYSTEM NOTICE

Auto translation by AI. Be sure, accuracy, nuances and authorial intent may not be fully reflected.
見出し画像

Are management decisions and government policies behind the spread of passkeys? [#SecurityBehindTheScenes 9]

This article is an archived version of the 9th episode of the podcast "Reading Between the Lines of Security," presented by EG Secure Solutions.

Have you ever used a passkey? Have you noticed that you've been seeing passkeys more often when logging in lately?

Some companies are moving away from SMS authentication and switching to passkeys. Yahoo! is one of them.

Why is there so much attention on passkeys right now? The background involves a complex mix of factors, including security considerations and corporate management decisions. Together with experts in security and management, we will explore the interesting knowledge behind the scenes and deepen our understanding of security.

🎙️ Listen to this podcast

🎙 About the commentators

  • Hiroshi Tokumaru (Expert): Chief Technology Officer (CTO) of EG Secure Solutions. A pioneer in Web security.

  • Teppei Takahata (Manager): A manager with extensive experience in the IT and Web marketing fields.

  • Honoka Kagawa (Navigator): A young employee. Security consultant and Web vulnerability assessor.


Introduction: Passkeys recommended despite the confusion

In the previous article, we explored what passkeys really are. Passkeys use a mechanism where a unique key pair is generated for each site, and the private key never leaves the device. This provides high security by preventing the risks of password reuse and phishing.

However, we are currently in a transitional period for adoption. With the background of the battle for supremacy between Apple and Google, multiple synchronization methods coexist, leading to variations in user experience, which has caused some complaints online.

Nevertheless, security expert Mr. Tokumaru recommends, "If you can use them, you should use them as much as possible."

Reasons for abandoning SMS authentication and moving to passkeys, as seen in the Yahoo! case

We confirmed the security of passkeys and the remaining operational confusion in the previous article. So, why is there so much attention on passkeys now? The clue lies in why Yahoo! abandoned the SMS authentication it relied on until recently. It is speculated that the background involves not only the security risks of SMS authentication but also the evolution of criminal methods and corporate cost factors.

The reason for switching from password authentication to SMS authentication in the first place

Tokumaru: Here, I'd like to talk about why passkeys are getting so much attention right now, but...

For example, Yahoo!. They released a statement saying they would consolidate to passkeys, but just before that, they were working hard on passwordless, but SMS authentication. In other words, they were working hard on a method where a 6-digit number is sent to a smartphone via SMS, and you enter it on your computer to log in, but they've stopped that, haven't they?

So, why did they stop SMS authentication? I won't say SMS authentication was bad, but I'll speculate in my own way. First of all, what was the reason for switching from password authentication to SMS authentication? For a company the size of Yahoo!, there are a huge number of users who have had their passwords broken for various reasons, such as phishing, password list attacks, or setting simple passwords. They would come crying for help, and the support for that became a huge burden. That cost is not negligible.

Tokumaru: And, actually, SMS authentication costs money.

Takahata: That's right.

Tokumaru: Takahata-san, you know this well. Unlike email, it always costs money, like 5 yen or some amount per message. They decided to commit to SMS authentication even if it meant paying that cost.

Why is SMS authentication discouraged? The threat and methods of "SIM swapping"

Tokumaru: However, NIST (National Institute of Standards and Technology) and other global standards are saying that SMS authentication is out of the question.

Kagawa: Why is that?

Tokumaru: They list several reasons why SMS authentication is dangerous. First, short messages are actually an old standard and are not particularly encrypted. That's why it's dangerous. Also, have you all heard of "SIM swapping"?

Kagawa/Takahata: SIM swapping?

Tokumaru: Yes. It's not that widespread, but they target the phone numbers of celebrities or wealthy people. They create fake IDs, like a fake driver's license for Takahata-san, go to a mobile phone shop, and say, "I'm sorry, I lost my smartphone, could you please reissue my SIM?" and sometimes it actually works.

Then, the SIM becomes usable with the same phone number. Takahata-san's smartphone suddenly stops working, and the newly issued one can receive short messages for Takahata-san's phone number. If they can authenticate for things like securities or online banking, they can steal money.

Takahata: That's clever.

Tokumaru: It's worth the effort and risk, so it was actually quite common in Japan for a while. The police would issue warnings every time it happened. But you know, there are so many mobile phone shops in the world, aren't there? There are so many in my local area alone. It's quite difficult to ensure that every single one of them can strictly verify identity.

It's hard to train part-time staff. So, perhaps that's why they decided to stop using SMS authentication.

SMS authentication is convenient but vulnerable to real-time phishing

Takahata: But it is quite convenient, isn't it?

Tokumaru: It is convenient. Also, SMS authentication is actually vulnerable to phishing.

Takahata: That was unexpected. It seems good at first glance, though.

Tokumaru: Yes. The reason is that a victim who opens a fake phishing screen first enters their ID and password. Then, the bad guys open the real site and log in with the ID and password they received. Then, a screen appears saying that a 6-digit number has been sent to the mobile phone. That 6-digit number arrives on the smartphone of the victim who has the fake screen open. Then, a screen asking to enter the 6-digit number appears on the victim's screen too. They think, "Oh, this one," and enter it. That's how it gets stolen.

So, that can be done with any type that requires entering a number. Since many two-factor authentication methods are vulnerable to phishing, that's why passkeys are getting attention now.

Takahata: So, it's not just saying that two-factor authentication is weak, but if you get tricked by a fake screen as the initial trigger, they automatically take it from there, right?

Tokumaru: Yes, I don't know how much of this is due to national character, but there are quite a lot of people who are honest and enter information as they are told. So, I think people will fall for it, yes.

Full compensation by companies without fault? The "bank strategies and government policies" behind financial institutions

Like real-time phishing, damage can occur even if there are no holes in a company's system. Even so, why have banks and securities firms agreed to provide compensation? Mr. Tokumaru deciphers the circumstances behind this from two contexts: bank strategy and national policy.

The inside story of full compensation by online banks

Takahata: We've covered the topic of things being stolen via SMS authentication, but it suddenly occurred to me, for example, in the case of a securities firm. I first saw it as something that didn't happen because of a flaw in the securities firm's system.

If anything, from the perspective of the target company, phishing is a matter of "that's being done on their own," and it's an event that occurred between the customer who was lured into entering their information and the bad actor. However, there's talk of companies providing some kind of compensation, and that really bothers me.

I don't understand why companies have to be blamed when they are actually completely unrelated, and while I understand why customers would be angry, there's also the thought, "Aren't you angry at the wrong person?" What is your take on this, Mr. Tokumaru?

Tokumaru: Yes. Returning to the topic of passwords for a moment, incidents involving online securities firms have been intensifying since about last year, but before that, online banking has existed since the internet began to spread. Even from the very early stages, incidents where deposits were illegally withdrawn or transferred were occurring.

In response to this, the Japanese Bankers Association, which is an organization of banks, made an agreement. A rule was first established that for individuals, the damage from unauthorized withdrawals—in other words, unauthorized transfers—would be fully compensated.

Takahata: Oh, I see.

Tokumaru: So, in the case of banks, if you ask who is at fault, at least in Japan, there hasn't been a case where money was withdrawn due to some major problem on the bank's side. Therefore, it's a case of the user being lured into phishing or getting a virus infection, right?

However, they decided to compensate, and I haven't heard of any major complaints from this or that bank; I think they did it with the feeling of, "Well, it can't be helped."

Now, as for the logic behind why they are doing this, I haven't heard this directly, but it's my speculation that, coming to this point, banks want to close their branches one after another. They want to shift to online.

Takahata: Yeah.

Tokumaru: If that's the case, there are still deep-seated voices saying, "No, even so, online is still worrying, isn't it?" or "Bank ATMs and counters are better." So, if it becomes a matter of self-responsibility where money is just stolen even if it's the user's fault, then online services probably won't spread.

Therefore, while it might be a different story if the damage amount were extremely large, I think the logic is that if it's within a range that can be sufficiently covered by the scale of the bank's management, then they might as well compensate.

Takahata: I see. It's a conclusion that you can either agree with or not (laughs).

Industry backlash against compensation requests, settled with full compensation for face-to-face securities and half for online securities

Tokumaru: There is more to the story. So, what about online securities? First, the Financial Services Agency requested that they provide compensation. This has no legal force, but they requested that they do so. This met with considerable backlash. Especially companies that operate mainly online were resistant. Just as you said, Mr. Takahata, "No, even so, it's not our responsibility, and the amounts are huge," right?

Tokumaru: As a conclusion, it was settled with major firms that are store-based (face-to-face securities) providing full compensation, and online firms providing half compensation.

This is probably because the Financial Services Agency, or the government, wants individuals to invest more and more, which would raise stock prices overall and make everyone who invests happy. If people say, "No, I don't want to invest anymore," then that would conversely shrink, so they want to revitalize investment. To that end, the perception that securities trading is dangerous is not good. I think there is a desire to ensure that even if something happens, people are protected.

Takahata: I see.

Passkeys eliminate "user negligence," not "implementation flaws."

Some say that the compensation practices we looked at in the previous section create a "moral hazard" that causes users to lose their sense of vigilance. On the other hand, Mr. Tokumaru takes the user's side, stating that businesses have an obligation to provide secure authentication methods. He points to passkeys as a solution.

However, even with passkeys, if there are flaws on the implementation side, the possibility of them being compromised remains. Mr. Tokumaru touched on the current state of security at some companies.

Passkeys prevent damage caused by "human error"

Kagawa: As a user, I'm grateful for the compensation, though, if something happens.

Tokumaru: That's true, yes. However, some people say this is a kind of moral hazard, a collapse of morals. But if you ask what the users' voices are, as you said, Takahata-san, they are understandable, but isn't there an obligation to provide something that is properly secure?

Password authentication is secure if users use it correctly, but it has become clear that doing so is extremely difficult. In other words, having to use 15 or more characters and not reusing them across other sites makes people wonder how they are supposed to use it.

Kagawa: It's also hard to manage, from the user's side.

Tokumaru: Yes, like "1Password, what's that?" On the other hand, with passkeys, there is no room for users to have to remember anything, so there is almost no chance of failure on the user's side. So, if we switch to that, I think a lot of that frustration will be resolved.

Even if you prevent damage from "human error," "implementation flaws" remain

Tokumaru: However, while I said there are no failures on the user's side, there is actually a small possibility of it being compromised if there are failures on the implementation side.

Kagawa: Is there?

Tokumaru: There is. I tweeted about this on X, so I'll say it: there was a flaw at a fairly prominent place, and thinking this was bad, I reported the vulnerability to the IPA (Information-technology Promotion Agency), and it was accepted. They should have been contacted already, but it's been about three months.

Kagawa: Is it okay to start talking about this here?

Tokumaru: It's fine, that's public information.

"A system to fix things quickly" is better than trendy security tools

Takahata: Well, there are plenty of companies where the number of vulnerabilities is not zero.

Tokumaru: That's right. So, everyone is making a fuss about Claude Mythos, aren't they? I think they should cut it out (laughs). The vulnerability I reported has been left for months, so why are they making a fuss about Mythos? Fix this first.

Takahata: Isn't the effort to fix things quickly more important?

Tokumaru: If you don't build a system to fix things quickly, even if you tentatively introduce Mythos, it'll be like a pie in the sky—you won't be able to make use of it.

Takahata: Yeah, that was... before there was even a right to use Mythos, they started discussions, and I wondered what they were even going to talk about.

Tokumaru: If company presidents gathered, what would they talk about? (laughs) Even if there was one scientist who was like a geek, it's not a topic where you could reach a conclusion there.

Takahata: Because there's nothing to say other than 'do your best to defend'.

Tokumaru: Well, like actively investing and hiring lots of talent, but right now, hiring is difficult.

Takahata: That's right. Well, if we get into this Mythos topic, it's going to become a huge, sprawling conversation.

Ending: The Misconception That 'Passkey = Biometric Authentication' That Even Experts Fall Into

Kagawa: So, we've decoded passkeys this time, and I'd like to use them more and more from now on.

Takahata: I agree. I feel like the fog in my mind has cleared, and I've decided to use them actively. I also understand the points where one might stumble in terms of convenience, so I feel a bit relieved.

Kagawa: Tokumaru-san, how was it for you to talk about this today?

Tokumaru: Yes. Actually, many security experts think that passkeys equal biometric authentication, and we need to correct this. A slide from a certain study group or meeting appeared on X, and it said 'Passkeys are biometric authentication,' and I was like, 'No, no, that's wrong.' (laughs)

Kagawa: I'd like to correct that.

Tokumaru: I wanted to correct it, yes.

Kagawa:Did you not correct it at that time?

Tokumaru:I'm a bit busy with various things right now. In the past, people used to say things like 'Tokumaru is throwing an axe,' but I'm keeping quiet for now.

Takahata:You're a moderate, after all.

Tokumaru:A moderate (laughs), yes. I'm very kind at heart.

Summary

Why is the passkey attracting attention now? Tokumaru cites Yahoo!'s transition to SMS authentication as an example, speculating that the deciding factor for the transition was not only the age of unencrypted standards and operational holes that cannot prevent SIM swapping, but also the weakness against real-time phishing.

Regarding the question of 'Why do companies compensate for damages caused by user negligence?', Tokumaru prefaces that companies have not admitted negligence, but speculates that for banks, it is a management decision to reduce physical branches and move online, and for securities companies, it is aimed at supporting the government's policy of 'from savings to investment'.

Passkeys significantly enhance security because they almost entirely eliminate risks caused by users. However, even if user-side risks are resolved, risks on the service provider side still remain. Mr. Tokumaru mentions cases of companies that leave vulnerabilities unaddressed, stating that building a system that allows for rapid fixes should be the priority.

Thank you for reading this far.

Through the content of this episode, we hope you have gained new insights and discoveries regarding security issues. Next time, we will discuss "AI-driven development," which is currently gathering a lot of attention.

If you would like to learn more about cybersecurity, which is closely related to our lives from the perspectives of corporate management and technology, please follow EG Secure Solutions' Note and our podcast. See you next time.

🎙️ Radio Decoding the Behind-the-Scenes of Security | Spotify | Apple Podcast | Amazon Music

About EG Secure Solutions

We are a group of security experts specializing in web application security. We provide a wide range of services, including web application vulnerability assessments, the "SiteGuard Series" WAF, systematic security education through "Security Campus," and consulting that works closely with companies. We support the realization of sustainable security tailored to the actual circumstances of each company.

Supplementary Information and References

Supplementary notes on terms and cases mentioned in the text

  • Handling of SMS authentication in NIST SP 800-63B: In the draft stage (2016), there was a description that out-of-band (OOB) authentication using SMS was "deprecated," but in the final version, it was revised to express conditions such as "use in combination with other authentication methods," "publication of risk assessment," and "provision of alternative means." In the latest Rev.4, it is categorized under a new classification called "restricted authenticator."

  • SIM Swapping: A technique where an attacker uses fake identification or other means at a mobile phone shop to reissue a SIM or perform a carrier switch (MNP), hijacking the victim's phone number to bypass SMS authentication. This has occurred within Japan, and a case involving a Tokyo Metropolitan Assembly member who reported being a victim was reported in April 2024.

  • Real-time Phishing: A technique where an attacker immediately relays the ID, password, and one-time code entered on a fake site to the real site to log in. Two-factor authentication methods that require "number entry," such as SMS, are inherently less resistant to this technique.

  • Moral Hazard: In the context of this article, this refers to the phenomenon where the sense of security provided by the knowledge that "the company will cover the full cost" leads to a decrease in the user's vigilance and duty of care regarding security, which in turn triggers careless behavior (such as clicking on suspicious links or reusing passwords).

  • Vulnerability Reporting to IPA (Information Security Early Warning Partnership): A public framework in Japan for safely reporting and fixing discovered software and website vulnerabilities. The IPA (Information-technology Promotion Agency, Japan) serves as the reception point for reports. For software products, JPCERT/CC contacts the product developers, and for websites, the IPA contacts the site operators directly to urge them to take countermeasures.

  • Claude Mythos: A model announced by Anthropic in June 2026. It possesses advanced security capabilities, such as the autonomous discovery of zero-day vulnerabilities, but due to the risk of misuse, it has not been released to the public and is provided only to participating organizations of Project Glasswing (such as Amazon, Apple, Cisco, and CrowdStrike) and select biomedical researchers.