Google has introduced Device-Bound Session Credentials (DBSC) to combat session hijacking attacks that have evolved from network-based cookie theft to malware-based credential stealing. DBSC uses public-key cryptography to bind sessions to specific devices, creating key pairs stored securely in hardware like TPM on Windows.

5m read timeFrom feistyduck.com
Post cover image
Table of contents
Selected Usenix Security ‘25 PapersShort News

Sort: