Home/Technology/Chrome adopts what may be the best protection yet against account takeovers

Chrome adopts what may be the best protection yet against account takeovers

TechnologyAugust 12, 20262 min readAttributed summary
Chrome adopts what may be the best protection yet against account takeovers
Device-bound session credentials thwart an increasingly common form of account takeover.
Reading Settings

Google’s Chrome browser has added a new feature that could go a long way in preventing a form of account takeover that’s grown increasingly common as users adopt two-factor authentication, passkeys, and similar protections.

The new Chrome protection is known as device-bound session credentials (DBSCs). The measure stores a unique encryption key in a silicon-resident fortress that’s built into the device running the browser. On Windows machines, this fortress is called a TPM, short for Trusted Platform Module. On macOS and iOS, it’s known as a secure enclave. Other platforms have differing names. Recently released versions of Chrome for Windows and macOS generate a key that’s stored in this fortress.

An antidote to session cookie theft

DBSCs protect against the theft of session cookies, the unique strings of characters that websites store on browsers. Session cookies greatly speed up browsing on sensitive sites that require user authentication. Instead of requiring the exchange of credentials each time a user opens a new site page, the server sets a session cookie that effectively proves the user has already successfully logged in.

Read full article

Comments

Source: Ars Technica

Related technology stories

Meta's Muse Is Better at Surveilling Than Helping Me
Sourced report
Source10 hours ago

Meta's Muse Is Better at Surveilling Than Helping Me

The Muse app continues Meta’s trend of opting users into data collection for AI training. It also nudges you to share your bank account, email, and passport information.

10 min briefingRead signal →