Chrome adopts what may be the best protection yet against account takeovers

← Back to the feed

Chrome adopts what may be the best protection yet against account takeovers

Ars Technica · 3 hours ago

Google has added a new security feature to Chrome called device-bound session credentials (DBSCs), designed to counter a growing method of account takeover that bypasses two-factor authentication and passkeys. Rather than exchanging login credentials repeatedly, websites use session cookies to confirm a user is already logged in, but these cookies can be stolen by infostealer malware or adversary-in-the-middle attacks and reused by criminals to hijack accounts. DBSCs tie session cookies to a unique encryption key stored in hardware, such as a Windows TPM or an Apple secure enclave, meaning stolen cookies alone can no longer grant access.

Under the new system, a browser must sign a form of the session cookie using the hardware-bound key each time a website issues a challenge, and since that key cannot be extracted from the secure chip, attackers who steal a cookie cannot complete the verification. The feature is currently limited to Chrome version 147 for Windows and version 150 for macOS, and even there it is enabled only for a small group of test users as Google evaluates it before wider rollout. Users can check whether it is active via Chrome's developer tools, and it remains unclear whether other Chromium-based browsers will adopt the technology.

  • Chrome adds device-bound session credentials to stop cookie-theft account takeovers
  • Session cookies now tied to hardware keys attackers cannot extract or copy
  • Currently limited testing on Chrome 147 (Windows) and 150 (macOS)

Art Culture

Read the full article at the source →