ZeroHour
Ars Technica · Securitypublished ()ingested Dan Goodin

Chrome adopts what may be the best protection yet against account takeovers

infoToolsimportance 48
AI summary · glm-5.3-flash

Chrome adopts device-bound session credentials that tie login sessions to a specific device, defending against cookie-theft account takeover attacks.

Chrome is adopting device-bound session credentials, which bind authenticated sessions to the physical device rather than to transferable cookies. The mechanism targets a common account takeover technique in which attackers steal session cookies and replay them on other machines. Ars Technica characterizes it as possibly the strongest protection yet against this class of takeover, which has become increasingly common.

  • Sessions become device-bound instead of cookie-portable
  • Targets cookie-theft-based account takeover
  • Could blunt infostealer-driven session hijacking
VendorsGoogle
ProductsChrome
OrganizationsArs Technica
Full article

Device-bound session credentials thwart an increasingly common form of account takeover.

This source does not provide full text. Read it at arstechnica.com.