🔒Chrome Adds Device-Bound Session Credentials for Enhanced Security
New Chrome Feature Shields Your Login Sessions from Hackers
TL;DR
Google Chrome now includes Device-Bound Session Credentials (DBSCs) to protect against session cookie theft. This new security feature uses unique encryption keys stored in hardware fortresses like TPM and secure enclaves, making it harder for attackers to steal your login sessions.
Chrome has rolled out a new security feature called Device-Bound Session Credentials (DBSCs), which aims to prevent account takeovers by securing session cookies with hardware-based encryption. This is crucial as two-factor authentication and passkeys are becoming more common, but also making session cookie theft a bigger threat. DBSCs generate unique keys stored in TPM or secure enclaves on Windows and macOS, ensuring attackers can't steal these keys. Chrome version 147 for Windows and 150 for macOS support this feature.

Key Points
Chrome version 147 for Windows and 150 for macOS support DBSCs.
DBSCs store unique encryption keys in TPM (Windows) or secure enclaves (macOS/iOS).
Attackers can't steal the private key from these hardware fortresses.
Web servers store visitor's public key under this new model, sending an authentication challenge.
Users can check if DBSCs are active by opening developer tools and looking for 'device bound sessions'.
Why It Matters
If you use Chrome with two-factor authentication or passkeys, DBSCs offer enhanced protection against session cookie theft. This feature is particularly important for users on Windows (Chrome v147) and macOS (v150). However, it's currently limited to a subset of users.
Frequently Asked Questions
Why does this matter?
If you use Chrome with two-factor authentication or passkeys, DBSCs offer enhanced protection against session cookie theft. This feature is particularly important for users on Windows (Chrome v147) and macOS (v150). However, it's currently limited to a subset of users.
What happened?
Google Chrome now includes Device-Bound Session Credentials (DBSCs) to protect against session cookie theft. This new security feature uses unique encryption keys stored in hardware fortresses like TPM and secure enclaves, making it harder for attackers to steal your login sessions.
Comments
Be the first to comment
Enjoyed this article?
Get it daily. 7am. Free. Reads in 5 minutes.
Join 2,881 builders reading daily.