The Actual News

Just the Facts, from multiple news sources.

Chrome adopts what may be the best protection yet against account takeovers

Chrome adopts what may be the best protection yet against account takeovers

Summary

Google Chrome has introduced a new security feature called device-bound session credentials (DBSCs) to prevent account takeovers by protecting session cookies with a unique encryption key stored in the device’s hardware. This feature currently works on Chrome for Windows and macOS and aims to stop attackers from using stolen session cookies to access user accounts.

Key Facts

  • DBSCs store an encryption key inside a secure area of the device, such as a Trusted Platform Module (TPM) on Windows or a Secure Enclave on Apple devices.
  • Session cookies help websites remember logged-in users without asking for a password every time.
  • Attackers have been stealing session cookies to bypass two-factor authentication and passkeys.
  • DBSCs require the stolen cookie to be signed with the private key stored safely on the user’s device, which attackers cannot access.
  • The new feature is available in Chrome version 147 on Windows and 150 on macOS, but only for some users as part of limited testing.
  • Users can check if DBSCs are active by looking in Chrome’s developer tools under the application tab.
  • Other browsers based on Chromium may add DBSC support in the future.
  • DBSCs and passkeys are new security methods that do not rely on shared secrets like passwords or static codes.
Read the Full Article

This is a fact-based summary from The Actual News. Click below to read the complete story directly from the original source.

Save articles & personalize your feed — Create a free account