Notes, ideas and lessons from cybersecurity, CIAM, identity, AI and technology.
Hong Kong SFC Moves Beyond OTP: Why Passkeys Are Becoming the New Standard for Internet Trading
A Significant Change in Authentication On 9 July 2026, the Hong Kong Securities and Futures Commission (SFC) issued a new circular requiring internet brokers and SFC-licensed virtual asset service providers (VASPs) to adopt robust, phishing-resistant authentication methods to protect clients’ trading accounts. One part of the circular immediately caught my attention: The SFC does not consider OTP to be a phishing-resistant authentication solution. The SFC specifically says that internet brokers and VASPs should not use email OTPs or SMS OTPs for client login and device-binding processes. ...
Building My GitHub Blog with Hugo and PaperMod: From 404 to Deployment
In this post, I walk through setting up a blog with Hugo and PaperMod and fixing the deployment problems encountered on GitHub Pages.