💻 Technology · Ars Technica
Chrome adopts what may be the best protection yet against account takeovers - Ars Technica
From Ars Technica via USVI News: Device-bound session credentials thwart an increasingly common form of account takeover.
Google’s Chrome browser has added a new feature that could go a long way in preventing a form of account takeover that’s grown increasingly common as users adopt two-factor authentication, passkeys, and similar protections.
The new Chrome protection is known as device-bound session credentials (DBSCs). The measure stores a unique encryption key in a silicon-resident fortress that’s built into the device running the browser. On Windows machines, this fortress is called a TPM, short for Trusted Platform Module. On macOS and iOS, it’s known as a secure enclave. Other platforms have differing names. Recently released versions of Chrome for Windows and macOS generate a key that’s stored in this fortress.
For the moment, DBSCs are supported only in Chrome version 147 for Windows and 150 for macOS. Even then, DBSCs are turned on only for a limited set of users. Presumably, Google is testing the feature before making it generally available. Chrome users on Windows and macOS can check whether it’s running in their browser by opening developer tools, clicking on the application tab across the top, and scrolling down. When a user is logged into a site that supports DBSCs, “device bound sessions” will appear if the protection is turned on.
It’s unclear when, or if, other Chromium-based browsers will implement DBSCs, but it’s likely they will be coming.
For anyone curious this is being worked on as a W3C standard and the work for it has been going on for months. https://w3c.github.io/webappsec-dbsc/
1. Energy IPOs surge as investors hunt for ways to play AI boom
2. New surveillance tech links your phone to your license plate
3. Trump wants Big Pharma to split MMR vaccine; Big Pharma thinks it's idiotic
4. Chrome adopts what may be the best protection yet against account takeovers
5. New Pass-ta-key attack reveals all the things we didn't know about passkeys
This article is republished through the USVI News affiliate desk. Reporting, analysis, and viewpoints are those of the original publisher and do not necessarily reflect USVI News.