Chrome introduces device-bound session credentials to block account takeovers

Google Chrome is adopting a new security feature called device-bound session credentials to protect users from account takeovers. This mechanism ties authentication session tokens to a specific device, preventing attackers from stealing and reusing them elsewhere. The move addresses an increasingly common attack method where cybercriminals hijack valid session cookies to bypass passwords and two-factor authentication. By binding credentials to the device, even a stolen token becomes useless to an attacker operating from a different machine.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in