Here are this week’s topics that you don’t wanna miss out on!
💸 Payday Super: How SMS OTP costs explode in 2026
🏦 MFA Update to Malaysian Central Bank Risk Management
From 1 July 2026 Australian employers have to pay super with every payroll run, which turns a member who logged in 4 times a year into one who logs in 24 times or more. At 5 cents per SMS OTP that stops being a rounding error. A fund with 1 million members goes from roughly 230,000 dollars a year to 1,380,000. Funds carrying 2 to 4 million members land between 4 and 6 million, and two more deadlines hit the same window, SuperStream 3.0 and the ACMA Sender ID Register, so the SMS channel gets pricier and more regulated at once.
The security argument for keeping it is gone too: SS7 is unencrypted and exploitable through SIM swapping or reverse-proxy phishing, and AustralianSuper’s credential stuffing incident cost members 750,000 dollars out of just 10 accounts.
UniSuper, 130 billion dollars under management, already shipped passkeys and pays nothing per login after the first enrollment. The post breaks down per-provider SMS pricing and a three-phase enrollment plan that clears 80 percent adoption in a few quarters, which raises the uncomfortable question: if your login volume is about to sixfold, who is signing off on the per-message budget?
Bank Negara Malaysia’s November 2025 RMiT update quietly changed the verb. Guidance about stronger authentication became a binding requirement for every licensed bank, insurer, e-money issuer, payment operator and remittance institution in the country.
They now have to run MFA that is “more secure than unencrypted SMS” and “resistant to interception or manipulation”, which reads as an exit notice for the SMS second factor. The policy also defaults to one mobile device per account holder with an explicit opt-in for more and it wants the authentication code tied to the confirmed beneficiary and the amount, so transaction signing arrives without being called that.
Malaysian banks blocked over 383 million Ringgit of fraudulent transactions in 2024, so nobody is theorizing here. The post puts the five changes next to the old baseline and shows why passkeys cover the phishing-resistance, passwordless and device-binding clauses in a single move. Singapore, Australia and India are drifting the same way, so which regulator forces your hand first?
The FIDO Alliance India Working Group Meetup and Workshop runs on Friday 7 August, 9:00 to 16:00 IST, at Google Ananta in Bengaluru. I am on the agenda with a “Passkeys explained” session, alongside Nishant Kaushik on the FIDO technical roadmap, Lee Campbell, Niharika Arora and Eiji Kitamura from Google on Android and Chrome, SETS on Aadhaar and passwordless, plus adoption stories from PhonePe, MakeMyTrip and Visa. Given the two posts above, India is exactly the market where the SMS OTP question gets decided at scale next.
Payday Super and RMiT push you to the same place, an authentication flow you are about to rebuild without SMS sitting in the middle of it. Corbado Observe splits that flow into its subflows and shows what happens inside each one, which step users clear, which one they quietly abandon and where the fallback keeps getting triggered. Watch a real flow get taken apart in the video below.
Our mission is to free the world from passwords to make the Internet a safer place - this can only be accomplished together.
Join our passkeys community to connect with other passkey enthusiasts, stay up-to-date, get implementation support and show your passkeys projects!
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.