Urgent.News

What's breaking now, across thousands of outlets.

AI

Chrome adopts what may be the best protection yet against account takeovers

Device-bound session credentials thwart an increasingly common form of account takeover.

Chrome adopts what may be the best protection yet against account takeovers

Google’s Chrome browser has introduced a new feature dubbed device-bound session credentials (DBSCs) that promises to be a robust safeguard against account takeovers. This novel security measure stores a distinct encryption key in a hardware-based vault embedded within the device running the browser. In the case of Windows machines, this vault is referred to as a Trusted Platform Module (TPM).

On macOS and iOS, it is known as a secure enclave. Various platforms have their own terminology for these secure storage areas. Recent releases of Chrome for Windows and macOS generate a key that is securely stored in this vault. These DBSCs serve as an effective countermeasure against the theft of session cookies, which are unique alphanumeric strings that websites store in browsers.

Session cookies significantly expedite browsing on websites that necessitate user authentication, as they eliminate the need for repeated entry of credentials. Instead of requiring a fresh exchange of credentials for every new page a user opens, the server sets a session cookie that essentially validates the user’s prior successful login.

Written by urgent.news from Ars Technica's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at arstechnica.com →

More in AI

More from Tuesday 11 August →