To counter cookie theft, Chrome ships device-bound session credentials
ID: e27a9850-0140-51f7-8a8c-08fd6cb2d67a
STIX ID: report--e27a9850-0140-51f7-8a8c-08fd6cb2d67a
Feed Name: Help Net Security
This article explains Google's Device Bound Session Credentials (DBSC), a W3C-standard protocol that cryptographically binds web session cookies to device-specific hardware-backed keys (TPM on Windows, Secure Enclave on macOS) to prevent cookie theft and unauthorized session renewal. It covers how DBSC works, its privacy properties, industry collaboration and origin trials, observed reductions in session theft at Google, and planned enhancements for federated identity, advanced registration, and broader device support.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
