logo

I Love Device-Bound Session Credentials, But They Are Still Phishable and Hackable

ID: 4bec9216-f95c-5210-bb7b-5158b8814cd7

STIX ID: report--4bec9216-f95c-5210-bb7b-5158b8814cd7

Feed Name: KnowBe4 Blog

Date Published: 2026-06-11

Date Updated: 2026-06-11

Author: Roger Grimes

...
...

This article explains Google’s Device-Bound Session Credentials (DBSC) for Chrome/Workspace: how cookies work, the DBSC registration and short-lived cookie refresh flow tied to hardware secure elements (TPM/Secure Enclave), and the protections DBSC provides against traditional cookie theft. It also outlines DBSC limitations — including phishing, MitM, local malware, account re-registration abuse, and deployment adoption challenges — and concludes that DBSC reduces some risks but is not a complete solution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.