今日已更新 344 条资讯 | 累计 37249 条内容
关于我们

Chrome adopts what may be the best protection yet against account takeovers

Dan Goodin 2026年08月12日 04:59 3 次阅读 来源:Ars Technica

Device-bound session credentials thwart an increasingly common form of account takeover.

Google’s Chrome browser has added a new feature that could go a long way in preventing a form of account takeover that’s grown increasingly common as users adopt two-factor authentication, passkeys, and similar protections. The new Chrome protection is known as device-bound session credentials (DBSCs). The measure stores a unique encryption key in a silicon-resident fortress that’s built into the device running the browser. On Windows machines, this fortress is called a TPM, short for Trusted Platform Module. On macOS and iOS, it’s known as a secure enclave. Other platforms have differing names. Recently released versions of Chrome for Windows and macOS generate a key that’s stored in this fortress. An antidote to session cookie theft DBSCs protect against the theft of session cookies, the unique strings of characters that websites store on browsers. Session cookies greatly speed up browsing on sensitive sites that require user authentication. Instead of requiring the exchange of credentials each time a user opens a new site page, the server sets a session cookie that effectively proves the user has already successfully logged in. Read full article Comments
本文内容来源于互联网,版权归原作者所有
查看原文