I Love Device-Bound Session Credentials, But They Are Still Phishable and Hackable
ID: 4bec9216-f95c-5210-bb7b-5158b8814cd7
STIX ID: report--4bec9216-f95c-5210-bb7b-5158b8814cd7
Feed Name: KnowBe4 Blog
This article explains Google’s Device-Bound Session Credentials (DBSC) for Chrome/Workspace: how cookies work, the DBSC registration and short-lived cookie refresh flow tied to hardware secure elements (TPM/Secure Enclave), and the protections DBSC provides against traditional cookie theft. It also outlines DBSC limitations — including phishing, MitM, local malware, account re-registration abuse, and deployment adoption challenges — and concludes that DBSC reduces some risks but is not a complete solution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
