Protecting Cookies with Device Bound Session Credentials
ID: 46b65029-a525-563f-bea2-df9c7784879e
STIX ID: report--46b65029-a525-563f-bea2-df9c7784879e
Feed Name: Google Online Security Blog
Google announces Device Bound Session Credentials (DBSC) entering public availability for Windows in Chrome 146 (with macOS support coming), a protocol that uses hardware-backed keys (TPM/Secure Enclave) to cryptographically bind browser sessions to a device so exfiltrated cookies cannot be reused by attackers. DBSC preserves user privacy by issuing per-session keys without leaking device identifiers, is being standardized through W3C, and includes planned enhancements for federated identity, advanced registration, and broader device support.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
